CVE-2026-3055

9.5 CISA KEV

Citrix · NetScaler

A critical out-of-bounds memory read vulnerability in Citrix NetScaler ADC and Gateway allows unauthenticated attackers to potentially leak sensitive memory contents when configured as a SAML IDP.

Executive summary

This critical vulnerability in Citrix NetScaler is being actively exploited in the wild and poses a severe risk of sensitive information disclosure.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) occurring when NetScaler ADC or Gateway is configured as a SAML identity provider. The flaw allows an unauthenticated attacker to trigger a memory overread, potentially exposing sensitive session data or credentials.

Business impact

With a CVSS score of 9.5, this vulnerability represents a critical threat to organizational security. Successful exploitation could lead to full compromise of user sessions or the exposure of sensitive internal data, potentially resulting in unauthorized lateral movement within the network. The similarity of this flaw to historical memory leak vulnerabilities, such as CitrixBleed, underscores the high risk of widespread impact and reputational damage.

Remediation

Immediate Action: Apply the vendor-provided patches immediately: update NetScaler ADC and Gateway to versions 14.1-66.59, 13.1-62.23, or 13.1-FIPS/NDcPP 37.262 and later.

Proactive Monitoring: Monitor system logs for anomalous SAML authentication requests or unusual memory usage patterns that could indicate exploitation attempts.

Compensating Controls: Ensure that Web Application Firewalls are configured to block suspicious traffic patterns directed at SAML IDP endpoints, though these should not be considered a replacement for patching.

Exploitation status

Public Exploit Available: Yes, a weaponized exploit exists, including a Metasploit module and various public proof-of-concept repositories.

Analyst recommendation

Due to the critical severity and confirmed active exploitation, this vulnerability requires an emergency response. Administrators must prioritize the installation of the specified patches across all affected NetScaler ADC and Gateway environments. Failure to act immediately exposes the organization to a high probability of successful compromise by malicious actors.

More Citrix CVEs

Sources