
Attackers are exploiting CVE-2024-8452 by sending oversized SAML requests to unauthenticated NetScaler endpoints, triggering heap overflow in the packet engine process. Successful compromise of perimeter gateways enables lateral movement into internal network segments behind the appliance. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/citrix-netscaler-saml-heap-overflow-cve-2026-8452
Post summary
The post reports attackers are actively exploiting CVE-2024-8452 by sending oversized SAML requests to unauthenticated NetScaler endpoints, causing a heap overflow that compromises perimeter gateways and enables lateral movement inside the network.
