CVE-2026-8452 PoC: Citrix NetScaler pre-auth RCE detection and exploitation
github.com | vulnerability | Critical | CVE-2026-8452 | #rce | #public-poc | #pre-auth | #network-security | #authentication | #citrix | #netscaler | #memory-corruption | #cwe-119 | #cve | #poc | #saml | #cve-2026-8452
Summary
watchTowr's PoC covers CVE-2026-8452, a pre-auth flaw in Citrix NetScaler ADC/Gateway reachable when SAML is configured; offsets target build 13.1-30.52, with fixes in 14.1-72.61 and 13.1-63.18.
Why it matters
This is a public pre-auth remote-code-execution PoC, and although offsets are hardcoded for a specific build, it materially lowers the exploitation barrier. NetScaler administrators should upgrade affected builds per the Citrix bulletin and restrict exposed Gateway/AAA surfaces; use the PoC only in explicitly authorized isolated environments.
- Vendor
- Citrix / NetScaler
- Product
- NetScaler ADC and NetScaler Gateway
- Affected versions
- NetScaler ADC and Gateway 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 13.1 FIPS/NDcPP before 13.1-37.272; vulnerable when configured with SAML SP/IdP or Gateway/AAA virtual-server roles
- CVSS
- 9.8
- Published
- Collected
Skip to content