CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4439

As cited

Copy frozen at (site build).

vulnerabilities

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs disclosed a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and Gateway affecting versions 13.1 before 13.1-63.18 and 14.1 before 14.1-72.61. The vulnerability exists in SAML signature validation where a heap overflow in the PrefixList attribute of the CanonicalizationMethod element allows an attacker to corrupt adjacent allocator metadata and achieve arbitrary code execution. The researchers demonstrated exploitation by overwriting a function pointer to execute shellcode, disable signal handlers to prevent automatic reboot, and obtain persistent root access via a webshell.

Why it matters: Organizations running NetScaler as a SAML-configured edge gateway face immediate remote code execution risk from unauthenticated attackers before any authentication occurs; apply patches to versions 13.1-63.18 or later and 14.1-72.61 or later immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs disclosed a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and Gateway affecting versions 13.1 before 13.1-63.18 and 14.1 before 14.1-72.61. The vulnerability exists in SAML signature validation where a heap overflow in the PrefixList attribute of the CanonicalizationMethod element allows an attacker to corrupt adjacent allocator metadata and achieve arbitrary code execution. The researchers demonstrated exploitation by overwriting a function pointer to execute shellcode, disable signal handlers to prevent automatic reboot, and obtain persistent root access via a webshell.

Why it matters: Organizations running NetScaler as a SAML-configured edge gateway face immediate remote code execution risk from unauthenticated attackers before any authentication occurs; apply patches to versions 13.1-63.18 or later and 14.1-72.61 or later immediately.

VendorsCitrix
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary