TGViewer
APT APT @apt_notes · 16.6K subscribers
Post #1202 11.4K
🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452)

Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the executable heap. Results in root RCE when NetScaler is configured as SAML SP or IdP.

Affected: NetScaler ADC/Gateway 14.1 < 14.1-72.61 and 13.1 < 13.1-63.18

🔗 Research:
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/

🔗 Source:
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

#citrix #netscaler #rce #preauth #saml #heapoverflow
  • ❤ 7
  • 👍 4
  • 🔥 4
More from @apt_notes
  1. Sep 1, 2026🔒 Certi-Bhai — IIS AppPool → NT AUTHORITY\SYSTEM via AD CS RPC A webshell under IIS AppPo…
  2. Aug 11, 2026Post #1201
  3. Aug 7, 2026ResetNightmare ResetNightmare (CVE-2026-27912) is a validation flaw in the Kerberos Change…
  4. Jul 24, 2026🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation Low-privileged doma…
  5. Jul 9, 2026💉 P³ — Shellcode Loader: Process Parameter Poisoning This loader implements a code inject…
  6. Jul 8, 2026GhostLock — CVE-2026-43499 This is a Linux kernel vulnerability found by VEGA that exists…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →