Citrix NetScaler critical flaw could leak data, update now
ID: ed21e84d-fb7c-5f26-884f-705bb257df27
STIX ID: report--ed21e84d-fb7c-5f26-884f-705bb257df27
Feed Name: Security Affairs
Citrix released security updates for two NetScaler vulnerabilities: CVE-2026-3055, a critical (CVSS 9.3) memory overread that can leak sensitive data on appliances configured as a SAML Identity Provider, and CVE-2026-4368, a race condition (CVSS 7.7) causing session mix-ups. There are no known public exploits yet, but customers are urged to check for the SAML IDP configuration (look for 'add authentication samlIdPProfile.*') and apply patches immediately due to the high severity and historical precedent of similar widespread exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
