Skip to main content

Share story

Security

Citrix patches CVE-2026-8451 NetScaler memory overread flaw in SAML IDP configs

Citrix has released security bulletin CTX696604 addressing CVE-2026-8451 in NetScaler ADC and NetScaler Gateway. The bulletin describes the vulnerability as insufficient input validation leading to memory overread. It applies when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP. The flaw is classified as CWE-125, an out-of-bounds read. It received a CVSS v4.0 base score of 8.8 with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N. The precondition requires the appliance to be configured as a SAML IDP. Administrators can verify exposure by checking the NetScaler configuration for the string add authentication samlIdPProfile .*. The bulletin provides details on the affected products and remediation steps including fixed builds for standard, FIPS and NDcPP variants.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Citrix and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...