CVE-2026-8452 PoC:Citrix NetScaler 预认证 RCE 检测与利用
github.com | 漏洞 | 严重 | CVE-2026-8452 | #rce | #public-poc | #pre-auth | #network-security | #authentication | #citrix | #netscaler | #memory-corruption | #cwe-119 | #cve | #poc | #saml | #cve-2026-8452
摘要
watchTowr 发布 CVE-2026-8452 检测与利用工具:针对 Citrix NetScaler ADC/Gateway 在 SAML(SP 或 IdP)配置下可达的预认证漏洞;偏移量按 13.1-30.52 构建硬编码,受影响版本为 14.1-72.61、13.1-63.18 之前。
为什么值得关注
这是公开的预认证远程代码执行 PoC,虽然代码针对特定版本硬编码,仍显著降低了利用门槛。NetScaler 管理员应立即按照 Citrix 公告升级受影响构建,并限制暴露的 Gateway/AAA 管理面;PoC 只能在明确授权的隔离环境中使用。
- 厂商
- Citrix / NetScaler
- 产品
- NetScaler ADC and NetScaler Gateway
- 受影响版本
- NetScaler ADC and Gateway 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 13.1 FIPS/NDcPP before 13.1-37.272; vulnerable when configured with SAML SP/IdP or Gateway/AAA virtual-server roles
- CVSS
- 9.8
- 发布时间
- 收录时间
Skip to content