logo

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

ID: d0a9744d-af18-5d2b-8e56-2c6226f6c33d

STIX ID: report--d0a9744d-af18-5d2b-8e56-2c6226f6c33d

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-31

Date Updated: 2026-05-05

Author: Abinaya

...
...

CISA has alerted organizations to CVE-2026-3055, a critical out-of-bounds read vulnerability in Citrix NetScaler ADC/Gateway appliances when configured as a SAML Identity Provider; active exploitation has been confirmed and the flaw is listed in CISA’s KEV catalog. The vulnerability can expose authentication tokens and credentials, enabling attackers to gain footholds in enterprise networks; CISA requires federal agencies to remediate by April 2, 2026 and urges all organizations to apply vendor mitigations or discontinue affected devices until secured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.