securityaffairs.com 3/29/2026, 2:06:14 PM · via preferred

Urgent Alert: NetScaler bug CVE-2026-3055 probed by attackers could leak sensitive data

Urgent Alert: NetScaler bug CVE-2026-3055 probed by attackers could leak sensitive data

U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Citrix NetScaler flaw, tracked as CVE-2026-3055, to its Known Exploited Vulnerabilities (KEV) catalog, with a CVSS score of 9.3. In March, Citrix issued security updates for two NetScaler vulnerabilities, including CVE-2026-3055, which allows unauthenticated attackers to leak…

First seen 2026-03-24T13:48:16.947Z · Last seen 2026-03-31T10:15:39.177Z

CyberSIXT Evidence Panel
Primary Source support.citrix.com
CISA KEV Not in KEV
Patch Patch Status Unknown

ATTACKERS are actively probing a critical Citrix NetScaler flaw, CVE-2026-3055, which can leak potentially sensitive data through a memory overread when NetScaler ADC or Gateway are configured as a SAML IDP, with a CVSS of 9.3. According to Rapid7 researchers, the advisory notes that systems set up as a SAML Identity Provider are vulnerable while default configurations are not, and Citrix urges immediate patching as similar memory-leak flaws were widely exploited in 2023.

The flaw stems from insufficient input validation and can be triggered without authentication to exfiltrate data from the appliance’s memory, and there are no known in-the-wild exploits at present. Observations from Defused Cyber and watchTowr Intel indicate active reconnaissance and probing activity, with researchers warning that in-the-wild exploitation could begin soon once exploit code circulates.

Citrix has released security updates and notes the vulnerability is likely to affect organisations using affected NetScaler versions in certain configurations. March 29, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline