Cybersecurity & Privacy — 2026-03-25

Critical Citrix NetScaler Vulnerability Exposes SAML-Enabled Edge Devices to Data Leaks

Citrix disclosed CVE-2026-3055 (CVSS 9.3), an out-of-bounds memory read in NetScaler ADC and Gateway affecting SAML IDP configurations. Unauthenticated remote attackers can leak sensitive data from device memory. A second vulnerability, CVE-2026-4368, introduces a race condition enabling user session mixup on gateway and AAA virtual servers. No in-the-wild exploitation or PoC has been observed yet, but security firms warn exploitation is likely once PoC code emerges. Affected versions span NetScaler 14.1 and 13.1 branches including FIPS variants.

1 sources
  1. Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) - Help Net Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE