CVE Tools
Back to feed
PoC public Citrix NetScaler ADC watchTowr Labs rce Citrix NetScaler Gateway Citrix

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

watchTowr Labs·By Sina Kheirkhah (@SinSinology)··21 min read
CVE Tools coverage

watchTowr Labs has published a proof-of-concept exploit for a pre-authentication remote code execution vulnerability in Citrix NetScaler ADC and NetScaler Gateway, identified as CVE-2026-8452. The flaw is a heap overflow triggered during the canonicalization of SAML signature data, specifically when processing an overly large PrefixList element within the SignedInfo block. Successful exploitation allows attackers to gain root-level code execution on affected appliances, which are widely used for enterprise remote access. Citrix addressed the issue in recent security bulletins; administrators must update NetScaler ADC and Gateway to version 14.1-72.61 or 13.1-63.18 immediately.

Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.

You know the drill - it’s the typical enterprise “please don’t be a bad person or we may have to fire you” speech. But, you know what’s coming soon. It’s your favorite part of the onboarding process when you’ve started a new role.…

Continue reading on watchTowr Labs