logo

CISA Issues Emergency Mandate as Critical 9.3 NetScaler Flaw “Bleeds” Admin Sessions

ID: a29ab413-eaa8-5cc1-b318-a79d1e63b110

STIX ID: report--a29ab413-eaa8-5cc1-b318-a79d1e63b110

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

**CVE-2026-3055 — Citrix NetScaler ADC/Gateway OOB Read:** A critical out-of-bounds read vulnerability in Citrix NetScaler ADC/Gateway (CVSSv4 9.3) can leak administrative session IDs via crafted requests to SAML and WS-Federation endpoints, enabling full appliance takeover; researchers observed active exploitation, the issue is listed in CISA's KEV catalog, and federal agencies must remediate by April 2, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.