Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055)
ID: 55367a7b-3968-524b-ae0b-c76cbf8cbe40
STIX ID: report--55367a7b-3968-524b-ae0b-c76cbf8cbe40
Feed Name: Help Net Security
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway—CVE-2026-3055, an input-validation memory overread that can expose active session tokens in SAML IDP configurations, and CVE-2026-4368, a race condition that can mix up user sessions on Gateway/AAA servers. Affected 13.x and 14.1 versions should be upgraded immediately; while no public proof-of-concept or in-the-wild exploitation has been reported, the flaws are low-complexity and target commonly used configurations, so organizations are urged to apply fixes and restrict network access to vulnerable appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
