logo

CVE-2026-3055: NetScaler Memory Disclosure Puts SAML-Enabled Edge Devices at Risk

ID: ea319d78-aed3-5c4f-a63d-ec3cf15ce09e

STIX ID: report--ea319d78-aed3-5c4f-a63d-ec3cf15ce09e

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Citrix has released fixes for two NetScaler vulnerabilities—CVE-2026-3055, a critical memory overread affecting SAML IdP configurations that can expose sensitive in-memory data, and CVE-2026-4368, a race condition that can cause user session mix-ups in Gateway/AAA deployments; affected versions are listed, no public exploitation or PoC was confirmed as of 2026-03-24, and defenders are advised to prioritize patching, triage based on feature exposure and internet reachability, and apply post-patch hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.