Cybersecurity & Privacy — 2026-03-25
Critical Citrix NetScaler Vulnerability Exposes SAML-Enabled Edge Devices to Data Leaks
Citrix disclosed CVE-2026-3055 (CVSS 9.3), an out-of-bounds memory read in NetScaler ADC and Gateway affecting SAML IDP configurations. Unauthenticated remote attackers can leak sensitive data from device memory. A second vulnerability, CVE-2026-4368, introduces a race condition enabling user session mixup on gateway and AAA virtual servers. No in-the-wild exploitation or PoC has been observed yet, but security firms warn exploitation is likely once PoC code emerges. Affected versions span NetScaler 14.1 and 13.1 branches including FIPS variants.
1 sources
- Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) -
Help Net Security