非影资讯
面向安全从业者的中英双语安全研究与漏洞情报精选。

CVE-2026-8452 PoC:Citrix NetScaler 预认证 RCE 检测与利用

摘要

watchTowr 发布 CVE-2026-8452 检测与利用工具:针对 Citrix NetScaler ADC/Gateway 在 SAML(SP 或 IdP)配置下可达的预认证漏洞;偏移量按 13.1-30.52 构建硬编码,受影响版本为 14.1-72.61、13.1-63.18 之前。

为什么值得关注

这是公开的预认证远程代码执行 PoC,虽然代码针对特定版本硬编码,仍显著降低了利用门槛。NetScaler 管理员应立即按照 Citrix 公告升级受影响构建,并限制暴露的 Gateway/AAA 管理面;PoC 只能在明确授权的隔离环境中使用。
厂商
Citrix / NetScaler
产品
NetScaler ADC and NetScaler Gateway
受影响版本
NetScaler ADC and Gateway 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 13.1 FIPS/NDcPP before 13.1-37.272; vulnerable when configured with SAML SP/IdP or Gateway/AAA virtual-server roles
CVSS
9.8
发布时间
收录时间

原文 ↗

相关内容

返回