Memory Leaks and Mixed Sessions: NetScaler’s Critical 9.3 CVSS Flaw Demands Immediate Action
ID: 8ddce84c-c139-540b-9bea-136cf18e2c54
STIX ID: report--8ddce84c-c139-540b-9bea-136cf18e2c54
Feed Name: securityonline.info
On March 23, 2026 Cloud Software Group published a high-priority advisory for NetScaler ADC and NetScaler Gateway describing two vulnerabilities: CVE-2026-3055 (CVSS 9.3) — an insufficient input validation memory overread affecting NetScaler when configured as a SAML IDP that can expose device memory — and CVE-2026-4368 (CVSS 7.7) — a race condition causing session mix-ups on AAA or Gateway (SSL VPN/ICA/RDP Proxy) configurations potentially allowing session misattribution. The bulletin lists affected versions and immediate upgrade paths (e.g., 14.1-66.59, 13.1-62.23, and FIPS/NDcPP releases) and urges prompt patching; no active exploits have been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
