CVE-2026-8452
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 29 ago
Vulnerabilità · 85 giorni fa
Il punto non è che ogni NetScaler sia rotto. Il punto è che la fiducia nel singolo ruolo è saltata: una volta che l’appliance espone più funzioni, una sola patch non basta a chiudere la superficie esposta. SAML IdP, Gateway, load-balancing e HTTP/2 vanno trattati come percorsi distinti sulla stessa macchina.
Citrix e Cloud Software Group hanno pubblicato build corrette per NetScaler ADC e NetScaler Gateway 14.1-72.61 e 13.1-63.18, più le build FIPS 14.1-72.61 FIPS e 13.1.37.272. Le vulnerabilità divulgate includono CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816 e CVE-2026-13474; le conseguenze vanno da memory overread e overflow a lettura arbitraria di file e DoS, con impatto su configurazioni diverse.
Per gli ambienti con configurazioni miste o role-specific, il rischio resta quello di una correzione parziale: aggiornare il solo percorso SAML IdP lascia ancora esposti gli altri ruoli attivi sull’appliance.
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 29 ago
10 fonti che coprono questa storia
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Attackers wasted little time targeting the latest memory disclosure bug in Citrix NetScaler, after researchers published a proof-of-concept exploit.
Múltiples vulnerabilidades en NetScaler de Citrix
Citrix ha publicado 6 vulnerabilidades: 5 de severidad alta y 1 de severidad media que, en caso de ser
New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild
Citrix NetScaler received patches for another memory leak vulnerability similar to CitrixBleed, as well as memory overflow, file read and denial-of-service issues
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Arctic Wolf says Anubis affiliates abused RMM tools, VPN logins, RDP, PsExec, and cloud-transfer tools before ransomware deployment.
AL26-016 - Vulnerability impacting Citrix NetScaler CVE-2026-8451
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
Hackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response.
Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug.
Vulnerabilità in prodotti Citrix
Rilevate nuove vulnerabilità di sicurezza nei prodotti NetScaler ADC e NetScaler Gateway di Citrix.
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Security updates fix six NetScaler ADC and Gateway vulnerabilities, including 8.8-rated DoS bugs and unauthenticated file read.
Citrix patches a new NetScaler flaw with echoes of CitrixBleed
Citrix patched six NetScaler flaws, headlined by a high-severity memory disclosure bug (CVE-2026-8451) with striking similarities to CitrixBleed.
Kwetsbaarheden verholpen in Citrix Netscaler ADC en Netscaler Gateway Revisies
De kwetsbaarheden met de kenmerken CVE-2026-8451 en CVE-2026-10817 ontstaan door onvoldoende invoervalidatie, waarbij de software invoergroottes en -grenzen niet...
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fit into one of
Part of the PlainSec briefing for 2026-07-04