2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
Citrix NetScaler ADC and Gateway flaws enable memory information disclosure and user session mix-up; no active exploitation is observed yet.
Citrix patched CVE-2026-3055 (CVSS 9.3), an out-of-bounds read that can expose sensitive memory on systems configured as a SAML Identity Provider, and CVE-2026-4368 (CVSS 7.7), a race condition causing user session mix-up on Gateway and AAA virtual server configurations. Affected builds include NetScaler ADC and Gateway versions prior to 14.1-66.59 and 13.1-62.23. At publication there was no public evidence of active exploitation; CERT-EU recommends prioritizing internet-facing appliances, applying the Global Deny List mitigation, and terminating all sessions after patching.
- CVE-2026-3055 out-of-bounds read exposes sensitive memory on SAML IdP systems
- CVE-2026-4368 race condition allows one user to access another's session
- Global Deny List mitigation protects appliances without a reboot
- All active and persistent sessions must be killed after patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-3055 | Out-of-Bounds Read in Citrix NetScaler ADC and Gateway When Used as SAML IDP CVE-2026-3055 is an out-of-bounds read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the appliance is configured as a SAML Identity Provider (IDP). An unauthenticated remote attacker can trigger the flaw by sending crafted input to the SAML IDP functionality, causing the appliance to read beyond the bounds of allocated memory and potentially disclose sensitive information from it. The CVSS 4.0 base score of 9.3 (critical) reflects a network-vector flaw requiring no privileges or user interaction. Only organizations running NetScaler ADC or NetScaler Gateway appliances with SAML IDP configured are affected, according to the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-30, carries an 87.2% EPSS probability of exploitation within 30 days, has a public proof-of-concept, and headlines indicate active reconnaissance and exploitation against NetScaler deployments, including federal patch directives. Do: Apply the patched NetScaler ADC and NetScaler Gateway releases from Citrix's advisory as soon as possible, prioritizing internet-facing appliances (exact fixed version numbers are not in this data; check the vendor bulletin). Determine whether SAML IDP is configured on your appliances and, if it is not needed, disable or unbind it as an interim mitigation while reviewing appliance logs for suspicious authentication or reconnaissance traffic. Federal agencies must follow the CISA required action and BOD 22-01 guidance, with CISA directing patching by the stated Thursday deadline. | 9.3 | 87% | KEV PoC |
| largetens of thousands of internet-exposed NetScaler ADC/Gateway appliances, with the directly exposed subset limited to those configured as SAML IDPs | |
| CVE-2026-4368 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leadin Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup NVD description · AI analysis pending | 7.7 | 4% | — | — |
Full article392 words · extracted from cert.europa.eu · click to collapse
Release Date: 23-03-2026 18:03:59
History:
- 23/03/2026 --- v1.0 -- Initial publication
Summary
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway [1]. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations.
At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.
Technical Details
The advisory describes two vulnerabilities:
The vulnerability CVE-2026-3055, with a CVSS score of 9.3, is an out-of-bounds read vulnerability that may result in memory overread. Successful exploitation could allow an attacker to access sensitive information from memory. This issue affects systems configured as a SAML Identity Provider (IdP) [1].
The vulnerability CVE-2026-4368, with a CVSS score of 7.7, is a race condition that may lead to user session mix-up. Exploitation could allow one user to gain access to another user’s session. This issue affects systems configured as a Gateway (e.g. SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server [1].
Affected Products
The vulnerabilities affect NetScaler ADC and NetScaler Gateway versions:
- prior to 14.1-66.59
- prior to 13.1-62.23
- prior to 13.1-37.262 (FIPS and NDcPP) - only for NetScaler ADC
Citrix also identified a known issue in builds 14.1-66.54 and 14.1-66.59 affecting STA server binding configuration. When the STA server is configured using the full path (/scripts/ctxsta.dll), binding may fail, impacting authentication flows [2].
Additional information is available in the vendor’s advisory [1].
Recommendations
CERT-EU strongly recommends taking the following actions:
- restrict access to NetScaler Gateway and AAA virtual servers using network-level controls (e.g. IP allowlisting) until updates are deployed;
- where possible, apply Global Deny List (GDL) mitigation which enables mitigation without reboot and can help protect appliances [2];
- identify internet-facing appliances configured as SAML Identity Provider (IdP) or Gateway or AAA virtual server and prioritise their remediation due to exposure to CVE-2026-3055 and CVE-2026-4368;
- take snapshots of the appliances before patching them, as these may be needed later for investigating possible exploitation attempts;
- update vulnerable appliances;
- terminate all active and persistent sessions after patching to prevent attackers from reusing potentially compromised session tokens:
kill aaa session -all kill icaconnection -all kill rdp connection -all kill pcoipConnection -all clear lb persistentSessions References
[1] https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
Text extracted automatically; images, tables and formatting may be missing. Original: https://cert.europa.eu/publications/security-advisories/2026-003/