logo

Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation

ID: cddf3a97-e7f1-5ceb-9f27-973161801fec

STIX ID: report--cddf3a97-e7f1-5ceb-9f27-973161801fec

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Cybersecurity researchers report active reconnaissance targeting Citrix NetScaler ADC/Gateway appliances to identify instances vulnerable to CVE-2026-3055, a CVSS 9.3 unauthenticated memory overread that can leak sensitive memory when NetScaler is configured as a SAML IdP; attackers are probing the /cgi/GetAuthMethods endpoint via POST to fingerprint susceptible configurations, and administrators are urged to apply Citrix patches immediately to prevent imminent exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.