CISA Issues Emergency Mandate as Critical 9.3 NetScaler Flaw “Bleeds” Admin Sessions
ID: a29ab413-eaa8-5cc1-b318-a79d1e63b110
STIX ID: report--a29ab413-eaa8-5cc1-b318-a79d1e63b110
Feed Name: securityonline.info
Threat Score
**CVE-2026-3055 — Citrix NetScaler ADC/Gateway OOB Read:** A critical out-of-bounds read vulnerability in Citrix NetScaler ADC/Gateway (CVSSv4 9.3) can leak administrative session IDs via crafted requests to SAML and WS-Federation endpoints, enabling full appliance takeover; researchers observed active exploitation, the issue is listed in CISA's KEV catalog, and federal agencies must remediate by April 2, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
