logo

U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalog

ID: 328b3c92-bdb8-5626-a98f-97c61f700435

STIX ID: report--328b3c92-bdb8-5626-a98f-97c61f700435

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added a critical Citrix NetScaler vulnerability (CVE-2026-3055, CVSS 9.3) to its Known Exploited Vulnerabilities catalog; the flaw is an out-of-bounds read that can leak sensitive memory and affects Citrix ADC/Gateway configured as a SAML Identity Provider. Citrix released patches for this and a separate race condition (CVE-2026-4368); while there are no known in-the-wild exploits or public PoCs yet, CISA has ordered federal agencies to remediate by April 2, 2026, and organizations are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.