logo

Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities

ID: 709e5ce7-b33f-5e22-bd22-a970a717f402

STIX ID: report--709e5ce7-b33f-5e22-bd22-a970a717f402

Feed Name: Infosecurity Magazine (News)

Threat Score
60/100

Date Published: 2026-03-24

Date Updated: 2026-04-22

...
...

Citrix published a security bulletin for two vulnerabilities in NetScaler ADC/Gateway: CVE-2026-3055 (CVSS 9.3) is an out-of-bounds read that can disclose memory and affects systems configured as SAML Identity Provider; CVE-2026-4368 (CVSS 7.7) is a race condition that can cause session mix-up for certain Gateway/AAA vserver configurations. Only customer-managed appliances with those specific configurations are affected; Citrix released patches (14.1-66.59, 13.1-62.23, and FIPS/NDcPP updates) and Global Deny List signatures as temporary mitigations, and reported no known active exploitation or public PoC.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.