CVE-2026-8451
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
- Affected products
- Netscaler Adc, Netscaler Gateway
- Citrix Netscaler Application Delivery Controller
- < 13.1-37.272, 13.1-63.18, 14.1-72.61, 14.1-66.68
- Citrix Netscaler Gateway
- < 13.1-63.18, 14.1-72.61
- CVSS 4.0
- 8.8 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 15.7% (97th percentile)
- Weakness
- CWE-125
- NVD status
- Analyzed
- Published
- 2026-06-30
CVE-2026-8451 at NVD
6 known exploits for CVE-2026-8451
Proof-of-concept code and exploit modules indexed by Sploitus