vulnerability
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
Critical
Summary
A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parser, allowed for memory disclosure and was actively being probed by multiple threat actors. Organizations utilizing NetScaler appliances as SAML IDPs are urged to immediately patch or disable the feature to mitigate the risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data