You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
tech
Citrix NetScaler, which powers remote access and load balancing for thousands of enterprises, has a critical pre-authentication remote code execution vulnerability, per watchTowr Labs. The flaw occurs when NetScaler processes digitally signed SAML authentication messages—it performs a cleanup operation on the signature data, copying attacker-controlled bytes into a fixed-size buffer without checking if they fit, causing a heap overflow. An attacker can send a specially crafted message and achieve complete system compromise without logging in. The vulnerability affects NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18. This marks the first publicly documented NetScaler RCE in three years.
Source: https://labs.watchtowr.com/youre-back-in-the-room-citrix-...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton