CVE-2026-8451 is an input-validation flaw that can cause a memory over-read when NetScaler ADC or NetScaler Gateway is configured as a SAML identity provider. It is remotely exploitable without authentication, and the NetScaler CNA rates it CVSS v4.0 8.8 HIGH. The public primary record does not establish RCE or exploitation within 24 hours.
Vulnerability Overview and Scope of Impact
Affected ranges are ADC/Gateway 14.1 before 72.61, 13.1 before 63.18, ADC 14.1 FIPS before 72.61, and ADC 13.1 FIPS/NDcPP before 37.272. A deployment that is not configured as a SAML IdP does not meet this CVE's configuration prerequisite.
Measures Engineers Should Take Immediately
Confirm both the configuration and build, then update to 14.1-72.61, 13.1-63.18, 14.1 FIPS 72.61, 13.1 FIPS/NDcPP 37.272, or a later vendor-fixed release. Migrate unsupported branches to a supported train and follow NetScaler's official installation instructions.
📦