Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities
ID: 709e5ce7-b33f-5e22-bd22-a970a717f402
STIX ID: report--709e5ce7-b33f-5e22-bd22-a970a717f402
Feed Name: Infosecurity Magazine (News)
Citrix published a security bulletin for two vulnerabilities in NetScaler ADC/Gateway: CVE-2026-3055 (CVSS 9.3) is an out-of-bounds read that can disclose memory and affects systems configured as SAML Identity Provider; CVE-2026-4368 (CVSS 7.7) is a race condition that can cause session mix-up for certain Gateway/AAA vserver configurations. Only customer-managed appliances with those specific configurations are affected; Citrix released patches (14.1-66.59, 13.1-62.23, and FIPS/NDcPP updates) and Global Deny List signatures as temporary mitigations, and reported no known active exploitation or public PoC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
