CISA Warns of Active Exploitation of Critical Citrix NetScaler SAML RCE Flaw
A critical vulnerability tracked as CVE-2026-8452 in Citrix NetScaler ADC and Gateway is being actively exploited in the wild, according to CISA and security researchers. The flaw allows unauthenticated attackers to trigger a heap overflow through crafted SAML requests, which can be escalated to remote code execution with root privileges. WatchTowr Labs publicly demonstrated how the heap corruption can be used to execute shellcode inside the nsppe process running as root. Real-world attacks have involved deployment of PHP web shells, with attackers running discovery commands such as id and echo after gaining access. Administrators are urged to update to patched builds immediately, restrict public exposure of SAML endpoints, and investigate for web shells or credential compromise if a breach is suspected.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in