CVE-2026-8452 is a critical, pre-authentication heap overflow in how NetScaler ADC and Gateway parse SAML login messages, and attackers are using it right now to drop web shells, even though Citrix shipped a fix two months before anyone saw it exploited.

Read the full story: Citrix NetScaler CVE-2026-8452: Patched in June, Exploited in August →

Transcript

Citrix NetScaler admins, check your build number right now. There's a critical flaw, CVE-2026-8452, a heap overflow in the SAML login process that lets attackers break in without any credentials at all. CVSS score, eight point eight. Here's the part that stings. Citrix fixed this back in June. Attackers didn't start exploiting it until August, dropping web shells called x dot php and z dot php, then running basic commands to map out what they'd landed on. CISA added it to its known exploited list on August 26 and gave federal agencies until August 29 to patch. That deadline already passed. If you're not on build 14.1-73.32 or 13.1-63.21 or newer, assume you're exposed. Check for those web shell files, review your SAML logs, and patch today.