Critical Citrix NetScaler flaw gets official patch warning from CISA


  • CISA adds Citrix CVE-2026-3055 to the Known Exploited Vulnerabilities catalog, confirming exploits in the wild
  • Critical input validation flaw in NetScaler ADC/Gateway SAML IDP enables memory overflow and data access
  • Exploitation observed since March 27; ~30K NetScaler and 2K Gateway instances exposed, agencies to patch by April 2nd

The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new Citrix vulnerability to its catalog of known exploitable flaws (KEV), signaling exploits in the wild and urging government agencies to apply the fix immediately.

The bug in question is an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP. It can lead to memory overflow, which in practice can allow threat actors to access sensitive data or perform unauthorized actions.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top