logo

Memory Leaks and Mixed Sessions: NetScaler’s Critical 9.3 CVSS Flaw Demands Immediate Action

ID: 8ddce84c-c139-540b-9bea-136cf18e2c54

STIX ID: report--8ddce84c-c139-540b-9bea-136cf18e2c54

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

On March 23, 2026 Cloud Software Group published a high-priority advisory for NetScaler ADC and NetScaler Gateway describing two vulnerabilities: CVE-2026-3055 (CVSS 9.3) — an insufficient input validation memory overread affecting NetScaler when configured as a SAML IDP that can expose device memory — and CVE-2026-4368 (CVSS 7.7) — a race condition causing session mix-ups on AAA or Gateway (SSL VPN/ICA/RDP Proxy) configurations potentially allowing session misattribution. The bulletin lists affected versions and immediate upgrade paths (e.g., 14.1-66.59, 13.1-62.23, and FIPS/NDcPP releases) and urges prompt patching; no active exploits have been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.