logo

Critical Citrix NetScaler Vulnerability Exploited in the Wild

ID: 9ae7f1ed-173d-554a-9164-99a0e67a8b8e

STIX ID: report--9ae7f1ed-173d-554a-9164-99a0e67a8b8e

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

...
...

A critical Citrix NetScaler ADC/Gateway vulnerability (CVE-2026-3055, CVSS v4.0 9.3) allows unauthenticated attackers to trigger an out-of-bounds read and leak appliance memory on systems configured as SAML Identity Providers; researchers observed in-the-wild exploitation from honeypots and fingerprinting activity beginning March 27. Citrix, security researchers and national agencies urge immediate patching to the listed firmware versions and offer a temporary Global Deny List mitigation for specific builds while upgrades are scheduled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.