CVE Research
sekurity-team
InSEKurity of the Week (CW35/2026): Citrix NetScaler SAML Heap Overflow (CVE-2026-8452)
Citrix shipped the fix on June 30 and called it a denial of service. Seven weeks later watchTowr turned the same heap overflow into pre-auth root, and web shells landed on unpatched NetScaler appliances within days -- CISA added it to KEV on August 26 with a three-day deadline.
Exploit
01
