Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution

CVE-2026-8452 in Citrix NetScaler: how a SAML parsing overflow became pre-auth code execution From denial of service to remote code execution Citrix published fixes for CVE-2026-8452 in August 2026 and initially described the impact as denial of service. The affected builds were NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, including the FIPS and NDcPP…

CVE-2026-8452 is a vulnerability affecting Citrix NetScaler, allowing unauthenticated attackers to send specially crafted SAML input and potentially execute remote code before authentication. Initially described as a denial-of-service issue, researchers later discovered that the overflow could be leveraged to write a primitive, leading to remote code execution.

The CVSS score for this flaw is 8.8, classified as a memory buffer bounds weakness. Citrix released patches in August 2026, and the Common Vulnerabilities and Exposures (CVE) system added the vulnerability to its Known Exploited Vulnerabilities catalog the same month. Public measurements indicate around 22,000 NetScaler instances are reachable from the internet, and this attack pattern resembles previous campaigns targeting the same product line.

The root cause lies in the nsppe process, which handles inbound traffic, including SAML authentication, and runs with high privileges. A SAML configuration must be present on the appliance for the vulnerability to be triggered. The affected builds include NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, including FIPS and NDcPP variants.

To mitigate the risk, administrators should verify their appliance's firmware build against the recommended versions, inspect SAML configurations, and rotate certificates and signing secrets. Patching does not automatically remove established web shells, so a thorough inspection and rebuilding of the appliance may be necessary after upgrading.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 30 September →