• Sources: primary
  • Summary: watchTowr published an analysis of a heap overflow in the SAML handling of NetScaler ADC and Gateway, where canonicalization of an attacker-supplied assertion drives a memcpy whose source and destination are both attacker-controlled. The write-up chains that primitive to pre-authentication remote code execution. It reports Citrix listing NetScaler ADC and NetScaler Gateway 14.1 before 14.1-72.61 and NetScaler ADC and NetScaler Gateway 13.1 before 13.1-63.18 as affected. watchTowr states it believes but cannot confirm the flaw it analyzed is CVE-2026-8452, because Citrix does not correlate CVE identifiers with credited researchers.
  • Why it matters: NetScaler Gateway is the remote-access front door for large enterprises, and the write-up hands an unauthenticated attacker a memcpy with attacker-controlled source and destination on unpatched appliances configured to use SAML as either a service provider or an identity provider.

send feedback on this story