CVE-2026-3055

Published Mar 23, 2026

Last updated 19 days ago

Exploit knownCVSS critical 9.3
Server
Network
Ubuntu
VDI
Supply chain

Overview

Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Source
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
NVD status
Analyzed
Products
netscaler_application_delivery_controller, netscaler_gateway

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Citrix NetScaler Out-of-Bounds Read Vulnerability
Exploit added on
Mar 30, 2026
Exploit action due
Apr 2, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
CWE-125

Social media

Hype score
Not currently trending
  1. 🚨 Edge infrastructure is failing first — again. CISA just added two critical flaws to the KEV catalog: • Citrix NetScaler CVE-2026-3055 (memory overread via SAML IdP) • F5 BIG-IP APM CVE-2025-53521 (unauthenticated RCE) Both are actively exploited. New article → htt

    @ByteVanguardSec

    7 Apr 2026

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 💡IR/CERT Morning Brief (4/1) 1/ • Priority issues: NetScaler CVE-2026-3055 and BIG-IP APM CVE-2025-53521 • Supply chain follow-up: renewed attention on TeamPCP’s WAV/MsBuild delivery technique • Incident claim: alleged large-scale breach of Spain’s Feníe Energía

    @Team_D4rkn3ttz

    1 Apr 2026

    286 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  3. 💡IR/CERT Morning Brief (4/1) • Priority issues: NetScaler CVE-2026-3055 and BIG-IP APM CVE-2025-53521 • Supply chain follow-up: renewed attention on TeamPCP’s WAV/MsBuild delivery technique • Incident claim: alleged large-scale breach of Spain’s Feníe Energía •

    @Team_D4rkn3ttz

    1 Apr 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️Citrix NetScalerの最近の脆弱性に関連する偵察活動が確認される:CVE-2026-3055 🚨CISA、BIG-IP APMシステムのRCE脆弱性(CVE-2025-53521)をKEVカタログに追加 〜サイバーセキュリティ週末の話題〜 https://t.co/1r2usvLTuX

    @MachinaRecord

    30 Mar 2026

    278 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🧵 Doppelschlag bei kritischer Netzwerk-Infrastruktur: CVE-2025-53521 und CVE-2026-3055 bedrohen Tausende Unternehmen **Die vergangenen 48 Stunden haben zwei kritische Schwachstellen in fundamentaler Enterprise-Netzwerk-Infrastruktur ins Rampenlicht gerückt: F5 BIG-... https:

    @dirkalthausinv

    30 Mar 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CitrixBleed happened in 2023. LockBit used it to hit Boeing and ICBC. CitrixBleed2 happened in 2025. Salt Typhoon used it to backdoor a European telecom. Citrix just patched CVE-2026-3055. Same vulnerability class. Same product. CVSS 9.3. No auth required. Rapid7 and watchTowr

    @Atarussecurity

    27 Mar 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Top 5 Trending CVEs: 1 - CVE-2026-27522 2 - CVE-2026-3055 3 - CVE-2025-58718 4 - CVE-2026-20963 5 - CVE-2026-21858 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Mar 2026

    238 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations