logo

Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

ID: 715410d4-3bf0-50e6-8a11-0009ce5ad679

STIX ID: report--715410d4-3bf0-50e6-8a11-0009ce5ad679

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-07-22

...
...

Citrix released security patches for two critical NetScaler vulnerabilities—CVE-2026-3055 (unauthenticated out-of-bounds read, CVSS 9.3) and CVE-2026-4368 (race condition, CVSS 7.7)—which can expose authentication/session data and cause session confusion; organizations should urgently patch affected NetScaler ADC/Gateway versions, assess SAML IdP and edge deployments, and monitor for anomalous requests and session activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.