logo

Citrix urges admins to patch NetScaler flaws as soon as possible

ID: 466ab45f-6f59-5c4a-9f50-04c1ac5c9a4c

STIX ID: report--466ab45f-6f59-5c4a-9f50-04c1ac5c9a4c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Citrix released patches for two critical flaws in NetScaler ADC and NetScaler Gateway (CVE-2026-3055 and CVE-2026-4368): a memory overread in SAML IDP configurations that can expose session tokens and a race condition that can cause session mix-ups. The issues affect 13.1 and 14.1 builds (fixed in specific updates), and Shadowserver reports tens of thousands of NetScaler instances exposed online; vendors warn exploitation is likely once exploit code is public and urge immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.