Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-5777 | Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned. Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw. | 9.3 | 100% | KEV ransomware |
| massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of… | |
| CVE-2026-3055 | Out-of-Bounds Read in Citrix NetScaler ADC and Gateway When Used as SAML IDP CVE-2026-3055 is an out-of-bounds read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway caused by insufficient input validation when the appliance is configured as a SAML Identity Provider (IDP). An unauthenticated remote attacker can trigger the flaw by sending crafted input to the SAML IDP functionality, causing the appliance to read beyond the bounds of allocated memory and potentially disclose sensitive information from it. The CVSS 4.0 base score of 9.3 (critical) reflects a network-vector flaw requiring no privileges or user interaction. Only organizations running NetScaler ADC or NetScaler Gateway appliances with SAML IDP configured are affected, according to the available data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-30, carries an 87.2% EPSS probability of exploitation within 30 days, has a public proof-of-concept, and headlines indicate active reconnaissance and exploitation against NetScaler deployments, including federal patch directives. Do: Apply the patched NetScaler ADC and NetScaler Gateway releases from Citrix's advisory as soon as possible, prioritizing internet-facing appliances (exact fixed version numbers are not in this data; check the vendor bulletin). Determine whether SAML IDP is configured on your appliances and, if it is not needed, disable or unbind it as an interim mitigation while reviewing appliance logs for suspicious authentication or reconnaissance traffic. Federal agencies must follow the CISA required action and BOD 22-01 guidance, with CISA directing patching by the stated Thursday deadline. | 9.3 | 87% | KEV PoC |
| largetens of thousands of internet-exposed NetScaler ADC/Gateway appliances, with the directly exposed subset limited to those configured as SAML IDPs | |
| CVE-2026-4368 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leadin Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup NVD description · AI analysis pending | 7.7 | 4% | — | — |
Full article498 words · extracted from helpnetsecurity.com · click to collapse
Citrix has fixed two vulnerabilities in NetScaler ADC and NetScaler Gateway, with the more serious flaw (CVE-2026-3055) potentially allowing attackers to extract active session tokens from the memory of affected devices.
Anil Shetty, senior VP of Engineering with Cloud Software Group (Citrix’s parent company), stated on Saturday that Cloud Software Group “is not aware of any unmitigated exploit available for either CVE 2026-3055 or CVE 2026-4368.”
Still, as both vulnerabilities can be exploited in low-complexity attacks and are in solutions that are often targeted by attackers, the company has urged customers to upgrade to a fixed version as soon as possible.
The vulnerabilities (CVE-2026-3055, CVE-2026-4368)
NetScaler ADC (application delivery controller) is a networking appliance used for improving the performance, security, and resiliency of applications.
NetScaler Gateway is a solution that allows users to safely access internal company resources (e.g., apps, desktops, files) over the internet.
CVE-2026-3055 is caused by insufficient input validation and may lead to memory overread. CVE-2026-4368 is a race condition that leads to user session mixup, i.e., may expose one user’s session to another user.
“The Citrix advisory states that systems configured as a SAML Identity Provider (SAML IDP) are vulnerable [to CVE-2026-3055], whereas default configurations are unaffected. This SAML IDP configuration is likely a very common configuration for organizations utilizing single sign-on,” Rapid7 noted.
CVE-2026-4368 is only exploitable on appliances that are configured as a Gateway or an AAA virtual server.
Both vulnerabilities affect NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262.
Citrix-managed cloud services and Adaptive Authentication have been updgraded with the latest software updates by Cloud Software Group.
Act quickly!
According to the security bulletin, CVE 2026-3055 was identified internally by Citrix during a security review.
Rapid7 and Arctic Wolf researchers say that there is currently no publicly available proof-of-concept (PoC) exploit for CVE 2026-3055 nor detected in-the-wild exploitation.
That said, with security updates now available, attackers may soon reverse engineer the patch and create an exploit. The similarity between CVE 2026-3055 and the previously exploited CitrixBleed2 flaw (CVE-2025-5777) might spur attackers to do it sooner rather than later.
Aside from updating vulnerable appliances, organizations should also consider restricting access to them using network-level controls.
UPDATE (March 30, 2026, 06:20 a.m. ET):
WatchTowr says they’ve detected active reconnaissance against NetScaler instances for CVE-2026-3055. “Organizations running affected Citrix NetScaler versions in affected configurations need to drop tools and patch immediately,” they advised.
The company’s researchers have published a technical run-down of the flaw and have revealed how indicators of compromise might look. They also say that CVE-2026-3055 covers at least two memory overread vulnerabilities, and have published a script organization can use to identify vulnerable hosts in their estates.
UPDATE (March 31, 2026, 04:50 a.m. ET):
CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/03/24/netscaler-adc-gateway-cve-2026-3055/