1.
github.com | vulnerability | Critical | | original ↗ | #rce | #public-poc | #pre-auth | #network-security
watchTowr's PoC covers CVE-2026-8452, a pre-auth flaw in Citrix NetScaler ADC/Gateway reachable when SAML is configured; offsets target build 13.1-30.52, with fixes in 14.1-72.61 and 13.1-63.18.
Why it matters: This is a public pre-auth remote-code-execution PoC, and although offsets are hardcoded for a specific build, it materially lowers the exploitation barrier. NetScaler administrators should upgrade affected builds per the Citrix bulletin and restrict exposed Gateway/AAA surfaces; use the PoC only in explicitly authorized isolated environments.
Skip to content