Urgent.News

What's breaking now, across thousands of outlets.

Tech

Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment

1. Overview Article Title : CISA: Hackers now exploiting Citrix NetScaler RCE flaw in attacks Source : BleepingComputer / CISA / Citrix Publication Date : 2026-08-27 Original Link : BleepingComputer Related Sources : Citrix advisory CTX696604 , watchTowr Labs technical research , Bishop Fox verification guide , CISA KEV alert , JPCERT/CC Advisory Associated Malware, Threat Groups, CVEs, Products…

CVE-2026-8452 is a critical vulnerability in Citrix NetScaler that allows attackers to exploit a heap overflow caused by a flaw in the SAML parser. This affects NetScaler ADC and Gateway appliances, and can lead to remote code execution (RCE) with root privileges. Attackers can send a crafted SAML request to an unauthenticated endpoint, triggering the heap overflow due to missing bounds checks on fixed-length buffers during prefix list canonicalization.

WatchTowr Labs demonstrated this vulnerability and showed that it can be used to execute malicious shellcode with root privileges.

Once the exploit is successful, attackers can deploy PHP web shells (x.php or z.php) to execute arbitrary commands on the NetScaler appliance. This can lead to the discovery of sensitive information, such as user IDs and echo responses, and may allow for further lateral movement within the network. The vulnerability can be mitigated by applying patches and restricting public exposure of NetScaler Gateways and AAA servers.

However, after a compromise, administrators should look for signs of web shell deployment, unusual SAML requests, and abnormal appliance behavior.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Friday 28 August →