July 1, 2026
- Citrix patched six NetScaler ADC/Gateway flaws, led by CVE-2026-8451 (CVSS 8.8), a pre-auth memory overread in SAML IdP handling that leaks memory and can crash appliances — the latest entry in the "CitrixBleed" lineage. watchTowr Labs, which reported it in March, published its analysis and hinted more is coming. The Hacker News, watchTowr · Vulnerabilities & Exploits
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread