Cyber & Intelligence — 2026-03-31

CISA Orders Emergency Patching of Actively Exploited Citrix NetScaler Vulnerability

CISA added CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and Gateway (CVSS 9.3), to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers are probing authentication endpoints to enumerate enabled flows on SAML-configured appliances. Federal agencies have until April 2 to patch under BOD 22-01.

Analysis
CVSS 9.3 with active exploitation targeting SAML-configured appliances is a high-priority threat amid an already elevated cyber risk environment. The April 2 FCEB deadline gives agencies only two days to patch. NetScaler ADC devices are ubiquitous in enterprise environments. The attacker technique of probing /cgi/GetAuthMethods to fingerprint authentication flows suggests pre-exploitation reconnaissance rather than opportunistic scanning. With Iranian destructive operations accelerating (see Stryker wiper) and CISA operating at reduced staffing, the exploitation window for unpatched devices is unusually wide.
3 sources
  1. CISA orders feds to patch actively exploited Citrix flaw by Thursday - BleepingComputer
  2. Citrix NetScaler Under Active Recon for CVE-2026-3055 - The Hacker News
  3. CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out-of-Bounds Read - Rapid7

View in full brief →

UNCLASSIFIED // OPEN SOURCE