A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar
A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

Key points
- Citrix disclosed CVE-2026-8451, a high-severity flaw in NetScaler ADC and Gateway devices, on 30 June 2026.
- The flaw received a CVSS score of 8.8 out of 10.
- WatchTowr discovered the bug in March 2026 and published a working proof-of-concept exploit the same day Citrix patched it.
- Lupovis confirmed active exploitation attempts began less than 24 hours after disclosure.
- Affected organisations should upgrade to NetScaler ADC and Gateway version 14.1-72.61 or 13.1-63.18 without delay.
Citrix patched CVE-2026-8451 on 30 June 2026. It's a memory overread flaw, meaning a remote attacker can send a crafted request that tricks the device into reading beyond its intended memory boundary, spilling whatever sits nearby: credentials, session tokens, internal data that shouldn't be visible at all. It affects NetScaler ADC (Application Delivery Controller, a device that manages inbound network traffic) and NetScaler Gateway (the remote-access product that handles outside logins), but only on appliances configured as a SAML identity provider, the component that brokers single sign-on for staff logging in remotely.
We covered the patch batch the day it landed in our 1 July story on Citrix's six-flaw NetScaler release; what's changed since is that exploitation is confirmed.
Why should ordinary people care about this?
If your employer or bank routes logins through Citrix NetScaler, this flaw could hand criminals credentials before any password prompt appears. Watch for unexpected password-reset requests or odd account activity from 30 June onward.
Experts compared CVE-2026-8451 immediately to CitrixBleed (CVE-2023-4966), a similar memory-leaking flaw that hit major organisations worldwide in late 2023. Both flaws live in the same product line, both bleed data from memory, and both drew attackers within hours of going public.
The speed here was blunt. WatchTowr Labs published full technical details and a ready-to-run proof-of-concept on the same day Citrix disclosed the patch. Within 24 hours, Lupovis, a UK firm that runs decoy systems to catch attackers, spotted a single IP address sending a targeted exploitation payload against NetScaler devices. That address, 146.70.139[.]154, is hosted on M247, a provider Lupovis says appears frequently in opportunistic scanning.
Xavier Bellekens, Lupovis co-founder and CEO, wrote in a blog post that what the firm observed wasn't random probing. The payload matched WatchTowr's specific technique, flooding NetScaler's XML parser with whitespace characters to force it past its memory boundary. Bellekens tied it directly to the detection artifact WatchTowr published on 30 June 2026. By 3 July, Lupovis posted on X that it had "seen a lot more exploitation."
Cloud security firm Aviatrix warned, as first reported by Dark Reading, that a successful attack could give criminals an initial foothold and let them escalate privileges and move sideways through a victim's network. An Aviatrix spokesperson told Dark Reading the pattern fits a familiar playbook of attackers targeting edge devices for credential harvesting or selling initial access onward.
Citrix did not respond to Dark Reading's request for comment before publication.
Should you worry if patching takes time?
Patching is the right answer. If it can't happen immediately, disabling the SAML IDP configuration on the vulnerable appliance reduces exposure. Lupovis also recommends reviewing SAML login records from 30 June onward and blocking 146.70.139[.]154. The honest read here is that the CitrixBleed comparison isn't alarmism: devices still unpatched a week after a public PoC, against a confirmed live campaign, are in real trouble.



