chiprook
← Security
SecuritySeptember 30, 2026, 23:20

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE

CVE-2026-8452 in NetScaler ADC and Gateway (14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, including FIPS and NDcPP) lets an unauthenticated attacker achieve remote code execution via a SAML parsing overflow. CVSS is 8.8, and CISA added the flaw to its Known Exploited Vulnerabilities catalog with a 29 August 2026 remediation deadline.

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE
#Citrix#NetScaler#CISA
Read next
Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

CVE-2026-19490: NetScaler SAML Bypass Detection and Mitigation

Security

Exploit details for Citrix NetScaler CVE-2026-88772 reveal pre-auth shellcode path

Security

Two Unpatched Citrix NetScaler RCE Zero-Days Actively Exploited