CVE-2026-3055: NetScaler Memory Disclosure Puts SAML-Enabled Edge Devices at Risk
ID: ea319d78-aed3-5c4f-a63d-ec3cf15ce09e
STIX ID: report--ea319d78-aed3-5c4f-a63d-ec3cf15ce09e
Feed Name: SOCRadar Blog
Citrix has released fixes for two NetScaler vulnerabilities—CVE-2026-3055, a critical memory overread affecting SAML IdP configurations that can expose sensitive in-memory data, and CVE-2026-4368, a race condition that can cause user session mix-ups in Gateway/AAA deployments; affected versions are listed, no public exploitation or PoC was confirmed as of 2026-03-24, and defenders are advised to prioritize patching, triage based on feature exposure and internet reachability, and apply post-patch hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
