The Chonkerton

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

tech

Citrix NetScaler, which powers remote access and load balancing for thousands of enterprises, has a critical pre-authentication remote code execution vulnerability, per watchTowr Labs. The flaw occurs when NetScaler processes digitally signed SAML authentication messages—it performs a cleanup operation on the signature data, copying attacker-controlled bytes into a fixed-size buffer without checking if they fit, causing a heap overflow. An attacker can send a specially crafted message and achieve complete system compromise without logging in. The vulnerability affects NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18. This marks the first publicly documented NetScaler RCE in three years.

Source: https://labs.watchtowr.com/youre-back-in-the-room-citrix-...

Listen to this story

Hear this and more stories in a personalized audio briefing.

Open The Chonkerton