DEV Community
Follow
Citrix NetScaler CVE-2026-8452: SAML Heap Overflow to Root RCE and Web Shell Deployment
Hackers are actively exploiting a critical vulnerability in Citrix NetScaler ADC and Gateway devices. This flaw, identified as CVE-2026-8452, allows unauthenticated attackers to trigger a heap overflow via crafted SAML requests. Security researchers have demonstrated that this overflow can be leveraged for remote code execution with root privileges. In real-world attacks, threat actors have deployed PHP web shells like x.php and z.php on compromised appliances. The vulnerability targets internet-facing authentication boundaries, posing a significant risk to organizations. Attackers gain root access by executing shellcode within the nsppe process. Indicators of a compromise include anomalous SAML requests, PHP web shells, and executed discovery commands. Organizations must immediately update their NetScaler devices to patched versions and verify the actual builds. If a compromise is suspected, a thorough investigation of web shells, credentials, and sessions is necessary. This active exploitation necessitates prompt patching and vigilant monitoring of NetScaler appliances.