Citrix has patched a memory-corruption vulnerability in NetScaler devices that could allow unauthenticated attackers to compromise them.
The flaw, tracked as CVE-2026-8452 ,impacts NetScaler ADC and NetScaler Gateway. The vulnerability, when exploited, causes unpredictable system behavior and denial-of-service.
An analysis by security firm WatchTowr uncovered that the vulnerability could be exploited through a feature called SignedInfo that verifies authentication signatures. Specifically, the vulnerability is caused when NetScaler stores the canonicalized data in a fixed-size memory buffer.
“During signature canonicalization, earlier versions of the NetScaler solution copy attacker-controlled data from the SAML message’s ds element into a fixed-size global buffer, without checking whether it actually fits,” WatchTowr said.
To exploit the flaw, WatchTowr then used the PrefixList field to corrupt metadata. “This turned out to be straightforward. All we needed were the open, write and close syscalls to drop the string…onto disk as a webshell,” WatchTowr said.
Citrix patched the flaw in June. It is unclear if the flaw has been exploited in the wild.
Citrix flaws weaponized
Multiple threat actors have exploited Citrix NetScaler flaws in the past to target critical infrastructure, mainly for data theft as part of espionage campaigns.
In June, attackers exploited a Citrix flaw tracked as CVE-2026-8451, which researchers said began attracting exploitation attempts within hours of its disclosure. The flaw is a pre-authentication memory-overread vulnerability affecting NetScaler ADC and Gateway when configured as a SAML Identity Provider.
Last year, the Dutch cyber agency said attackers exploited Citrix flaws to target multiple organizations in the Netherlands. The agency said multiple critical organizations had been successfully attacked through Citrix NetScaler vulnerabilities, including CVE-2025-6543, which had been exploited as a zero-day.