Critical severity9.8CISA KEVNVD Advisory· Published Mar 23, 2026· Updated Jun 17, 2026
CVE-2026-3055
CVE-2026-3055
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Affected products
8cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:-:*:*:*range: >=13.1,<13.1-62.23
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:fips:*:*:*range: >=13.1,<13.1-37.262
- cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:ndcpp:*:*:*range: >=13.1,<13.1-37.262
- cpe:2.3:a:citrix:netscaler_gateway:*:*:*:*:*:*:*:*Range: >=13.1,<13.1-62.23
- NetScaler/Gatewayv5Range: 14.1
Patches
Vulnerability mechanics
References
3- labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/nvdExploitThird Party Advisory
- support.citrix.com/support-home/kbsearch/articlenvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
19- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposureTenable Blog · Aug 15, 2026
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively ExploitedThe Hacker News · Aug 5, 2026
- Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable serversHelp Net Security · Aug 3, 2026
- Hacker uses DeepSeek AI to autonomously attack vulnerable serversBleepingComputer · Jul 31, 2026
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsInfosecurity Magazine · Jul 31, 2026
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous AttacksThe Hacker News · Jul 31, 2026
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News · Jul 30, 2026
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous CyberattacksUnit 42 · Jul 30, 2026
- Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate NetworksCyber Security News · Jul 27, 2026
- CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public DisclosureCyber Security News · Jul 2, 2026
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-ServiceThe Hacker News · Jul 1, 2026
- Citrix patches a new NetScaler flaw with echoes of CitrixBleedCyberScoop · Jun 30, 2026
- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)watchTowr Labs · Jun 30, 2026
- Metasploit Wrap Up 05/29/2026Rapid7 Blog · May 29, 2026
- 30th March – Threat Intelligence ReportCheck Point Research · Mar 30, 2026
- Critical Citrix NetScaler Vulnerability Exploited in the WildInfosecurity Magazine · Mar 30, 2026
- Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)watchTowr Labs · Mar 29, 2026
- The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)watchTowr Labs · Mar 28, 2026
- Citrix Urges Immediate Patching for Critical NetScaler VulnerabilitiesInfosecurity Magazine · Mar 24, 2026