CISA KEV Alert 3/30/2026, 8:30:55 PM

CISA Adds CVE-2026-3055 to Known Exploited Vulnerabilities Catalogue

U.S. CISA adds a flaw in Citrix NetScaler to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Citrix NetScaler flaw, tracked as CVE-2026-3055, to its Known Exploited Vulnerabilities (KEV) catalog, with a CVSS score of 9.3. In March, Citrix issued security updates for two NetScaler vulnerabilities, including CVE-2026-3055, which allows unauthenticated attackers to leak…

First seen 2026-03-24T13:48:16.947Z · Last seen 2026-03-31T10:15:39.177Z

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-3055 to its Known Exploited Vulnerabilities catalogue. The entry covers Citrix NetScaler ADC, NetScaler Gateway, and NetScaler ADC FIPS and NDcPP appliances. Citrix NetScaler Out-of-Bounds Read Vulnerability permits memory overread when the device operates as a SAML identity provider.

The vulnerability is an out-of-bounds read weakness affecting SAML IDP configurations. Exploitation enables memory overread, potentially disclosing sensitive authentication data or session tokens. NVD rates this flaw 9.3 on the CVSS scale, marking it CRITICAL. Citrix has published a security bulletin with mitigation steps; however, comprehensive patch availability remains unspecified in current disclosures.

Active exploitation of this vulnerability is confirmed in the wild. CISA has not attributed the flaw to specific ransomware campaigns at this time. Federal agencies face a remediation deadline of 2026-04-02.

CISA requires Federal Civilian Executive Branch agencies to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. All organisations running affected NetScaler appliances should audit their SAML configurations and apply appropriate controls.

Full technical details are available via the NVD entry for CVE-2026-3055 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline