logo

Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks

ID: 7819b4da-2413-5d6c-ad21-20c7503e8574

STIX ID: report--7819b4da-2413-5d6c-ad21-20c7503e8574

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Citrix released security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities—CVE-2026-3055 (CVSS 9.3, out-of-bounds memory read allowing unauthenticated data leakage when configured as a SAML Identity Provider) and CVE-2026-4368 (CVSS 7.7, race condition leading to session mixup when used as a gateway or AAA server). Affected versions include 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23 (plus specific FIPS/NDcPP builds); Citrix urges customers to check for specific configuration strings and apply updates immediately despite no confirmed exploitation in the wild, citing previous NetScaler-targeting incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.