← Vulnerability feed

Vulnerability record · CVE-2026-3055 · published 23 March 2026

CVE-2026-3055: Citrix NetScaler ADC and Gateway SAML IDP memory overread

Citrix · Netscaler Application Delivery Controller

NetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memory read. The flaw is remotely reachable without authentication and is listed in CISA KEV, so it warrants urgent attention.

9.3 CVSS 4.0 Critical CISA KEV since 30 Mar 2026 EPSS 4.0% · top 9.7% CWE-125 · Out-of-bounds read
9.3CVSS 4.0 base score
4.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.3, CISA KEV listing with a short due date, and an exploit-tagged reference indicate active, unauthenticated remote exploitation.

What it is

NetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memory read. The flaw is remotely reachable without authentication and is listed in CISA KEV, so it warrants urgent attention.

Impact

An unauthenticated remote attacker can read memory beyond intended bounds, potentially exposing sensitive data such as credentials or session material. The CVSS 4.0 vector also indicates high integrity and availability impact, though the description only confirms the overread.

Attack surface

Reached over the network via the SAML IDP interface; the CVSS vector shows no privileges or user interaction required. Only deployments configured as a SAML IDP are exposed.

Exploitation

CISA added it to KEV on 2026-03-30 with a 2026-04-02 due date, and a third-party advisory carries an Exploit tag, indicating active exploitation. EPSS is 0.87166 (99.74th percentile), consistent with high likelihood.

What to do

  • Apply the Citrix vendor advisory CTX696300 fix immediately; treat as emergency patching.
  • If patching is not possible, follow CISA BOD 22-01 guidance or discontinue use of the affected SAML IDP configuration.
  • Restrict network access to NetScaler SAML IDP endpoints to trusted sources where feasible.
  • Review SAML IDP configurations and disable the role if not required.
  • Monitor Citrix and CISA advisories for updated mitigation instructions.

Detection

  • Inspect NetScaler and gateway logs for anomalous SAML IDP requests or malformed SAML assertions.
  • Hunt for unexpected outbound connections or data exfiltration from NetScaler appliances.
  • Correlate NetScaler access logs with known exploitation indicators from the WatchTowr advisory.
  • Alert on unusual memory or crash events on NetScaler instances acting as SAML IDP.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-3055 to the Known Exploited Vulnerabilities catalog on 30 March 2026 as "Citrix NetScaler Out-of-Bounds Read Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 April 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2026-3055), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.