Critical NetScaler ADC and Gateway Flaws Expose Systems to Remote Attacks
ID: 9fb7726c-efb0-5c0f-b813-d22b30affcc0
STIX ID: report--9fb7726c-efb0-5c0f-b813-d22b30affcc0
Feed Name: GBHackers
Cloud Software Group released an advisory for two security flaws in customer-managed NetScaler ADC and Gateway appliances: CVE-2026-3055 (critical memory overread, CVSS 9.3) affecting SAML IdP configurations that may expose sensitive memory, and CVE-2026-4368 (high severity, CVSS 7.7) — a race condition that can cause administrative/user session mixups in certain AAA or Gateway setups. The bulletin identifies affected builds, provides patched versions (notably 14.1-66.59, 13.1-62.23, and 13.1.37.262 for FIPS/NDcPP), offers configuration search strings to check exposure, and recommends immediate upgrades for customer-managed deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
