CISA orders feds to patch actively exploited Citrix flaw by Thursday
ID: 4327af28-efe2-52c3-a0e8-0be66aa4e126
STIX ID: report--4327af28-efe2-52c3-a0e8-0be66aa4e126
Feed Name: Bleeping Computer
Threat Score
CISA ordered federal agencies to urgently patch Citrix NetScaler appliances for CVE-2026-3055, an input-validation flaw affecting SAML identity provider configurations that can allow unauthenticated attackers to steal admin session IDs and potentially take over ADC/Gateway devices; Citrix issued patches on March 23, security firms observed active exploitation, and Shadowserver reports ~30,000 ADC and ~2,300 Gateway instances exposed online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
