CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Citrix has released patches for six NetScaler flaws, including a pre-auth memory overread vulnerability reminiscent of the CitrixBleed exploit.
📍 The outcome
Citrix released patches for six NetScaler bugs, including flaws that allowed file read and denial-of-service attacks. These fixes addressed a pre-auth memory overread vulnerability and other issues.
Citrix credited JPMorgan regarding these updates.
Epilogue added 40d ago, after coverage quieted.
Momentum
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The story so far
Citrix has patched six vulnerabilities affecting NetScaler ADC and Gateway appliances. The flaws include a pre-auth memory overread identified as CVE-2026-8451, as well as issues that could allow for file read attacks and denial-of-service (DoS) scenarios.
Coverage from The Hacker News, CyberScoop, and cyberpress.org emphasizes the similarities between the new vulnerability and the previous CitrixBleed flaw. Thestack.technology reports that Citrix credited JPMorgan in the process of pushing these fixes.
Future developments depend on the deployment of these fixes across affected appliances to mitigate the risks of file read and DoS attacks.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 45d ago.
Who reported it (5)
- Citrix patches a new NetScaler flaw with echoes of CitrixBleed CyberScoop · 46d ago
- Citrix NetScaler ADC and Gateway Flaws Expose Appliances to DoS and File Read Attacks cyberpress.org · 46d ago
- Citrix credits JPMorgan, pushes fixes for six ugly NetScaler bugs thestack.technology · 46d ago
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service The Hacker News · 46d ago
- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) watchTowr Labs · 46d ago broke it first
The obvious questions
What is CVE-2026-8451?
It is a Citrix NetScaler pre-auth memory overread vulnerability.
What are the primary risks associated with these flaws?
The vulnerabilities expose appliances to denial-of-service (DoS) and file read attacks.
Who was credited by Citrix regarding these fixes?
Citrix credited JPMorgan.
People, places & organizations
Topics
Related trends
White House AI Guidelines Exempt U.S. Open Models From Government Review
The White House prepares a new framework for artificial intelligence security reviews with exemptions for open models.
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has filed a lawsuit against alleged hackers following a yearslong campaign targeting her inner circle and leaking unreleased music.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to lower costs.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft is entering the "agentic era" of security with the launch of its first homegrown AI model and new cybersecurity tools.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
A data breach at the Tribeca Film Festival has resulted in the exposure of private contact information for high-profile Hollywood figures.
Claude Cowork escaped sandbox on Mac, gain full access to all files
Security experts have identified a vulnerability allowing the Claude Cowork AI agent to bypass virtual machine isolation and access local files on Mac systems.