www.infosecurity-magazine.com 3/24/2026, 3:22:02 PM · via preferred

Citrix Urges Immediate Patching for Critical NetScaler Vulnerabilities

U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Citrix NetScaler flaw, tracked as CVE-2026-3055, to its Known Exploited Vulnerabilities (KEV) catalog, with a CVSS score of 9.3. In March, Citrix issued security updates for two NetScaler vulnerabilities, including CVE-2026-3055, which allows unauthenticated attackers to leak…

First seen 2026-03-24T13:48:16.947Z · Last seen 2026-03-31T10:15:39.177Z

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ACCORDING to Infosecurity Magazine, Citrix has released a new critical security bulletin addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway.

The first, CVE-2026-3055, is a critical out-of-bounds read (CVSS v4.0 9.3) caused by insufficient input validation, potentially enabling an unauthenticated remote attacker to leak memory contents; it affects NetScaler ADC and Gateway versions 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and 13.1-FIPS/NDcPP before 13.1-37.262, but only for devices configured as a SAML IDP, with default configurations unaffected.

Citrix notes that only customer-managed instances are affected, not cloud-managed ones, and provides a method to identify SAML IDP configurations via the string “_add authentication samlIdPProfile *_.” Cloud Software Group has issued updated builds and Global Deny List signatures to mitigate CVE-2026-3055, with guidance that mitigations apply on 14.1-60.52 and 14.1-60.57 firmware builds.

A second flaw, CVE-2026-4368, is a high-severity race condition (CVSS v4.0 7.7) affecting 14.1-66.54 configurations when the appliance is set as Gateway or AAA Vserver, with a patch available in 14.1-66.59. There is no known in-the-wild exploitation or public PoC at the time of writing.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline