Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2026-8451 Details
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
A vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway due to inadequate input validation. This flaw can lead to a memory overread condition when either product is set up as a SAML Identity Provider (IDP).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026Exploitation: NoneAutomatable: YesTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 | NetScaler | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| citrix netscaler application delivery controller | < 13.1-37.272 >= 13.1, < 13.1-63.18 >= 14.1, < 14.1-72.61 14.1-66.68 |
CPE
Remediation
| |
| citrix netscaler gateway | >= 13.1, < 13.1-63.18 >= 14.1, < 14.1-72.61 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | NetScaler |