logo

Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055)

ID: 55367a7b-3968-524b-ae0b-c76cbf8cbe40

STIX ID: report--55367a7b-3968-524b-ae0b-c76cbf8cbe40

Feed Name: Help Net Security

Threat Score
60/100

Date Published: 2026-03-24

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway—CVE-2026-3055, an input-validation memory overread that can expose active session tokens in SAML IDP configurations, and CVE-2026-4368, a race condition that can mix up user sessions on Gateway/AAA servers. Affected 13.x and 14.1 versions should be upgraded immediately; while no public proof-of-concept or in-the-wild exploitation has been reported, the flaws are low-complexity and target commonly used configurations, so organizations are urged to apply fixes and restrict network access to vulnerable appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.