Critical Citrix NetScaler memory flaw actively exploited in attacks
ID: 03c588e3-718c-5210-b749-404dfbd1e8b6
STIX ID: report--03c588e3-718c-5210-b749-404dfbd1e8b6
Feed Name: Bleeping Computer
Hackers are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers, to extract authenticated administrative session IDs and potentially fully takeover devices. Researchers (watchTowr) observed reconnaissance and confirmed exploitation in the wild since March 27, described two distinct vulnerable endpoints (/saml/login and /wsfed/passive), released a detection script, and noted technical similarity to prior CitrixBleed incidents while ShadowServer reports tens of thousands of exposed instances though the exact vulnerable subset is unknown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
