logo

Citrix NetScaler critical flaw could leak data, update now

ID: ed21e84d-fb7c-5f26-884f-705bb257df27

STIX ID: report--ed21e84d-fb7c-5f26-884f-705bb257df27

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Citrix released security updates for two NetScaler vulnerabilities: CVE-2026-3055, a critical (CVSS 9.3) memory overread that can leak sensitive data on appliances configured as a SAML Identity Provider, and CVE-2026-4368, a race condition (CVSS 7.7) causing session mix-ups. There are no known public exploits yet, but customers are urged to check for the SAML IDP configuration (look for 'add authentication samlIdPProfile.*') and apply patches immediately due to the high severity and historical precedent of similar widespread exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.