CVE-2026-8451: Citrix NetScaler Application Delivery Controller

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

Affected products

  • Citrix NetScaler Application Delivery Controller: before 13.1-37.272 (fixed in 13.1-37.272); from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61); version 14.1-66.68 only
  • Citrix NetScaler Gateway: from 13.1, before 13.1-63.18 (fixed in 13.1-63.18); from 14.1, before 14.1-72.61 (fixed in 14.1-72.61)

Published 2026-06-30. Last modified 2026-07-01.