Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up
Citrix released patches for two NetScaler ADC and Gateway vulnerabilities, CVE-2026-3055 and CVE-2026-4368. CVE-2026-3055 is an out-of-bounds read (CVSS 9.3) that can let unauthenticated attackers leak appliance memory when configured as a SAML Identity Provider. CVE-2026-4368 is a race condition (CVSS 7.7) that can cause user session mix-ups on Gateway or AAA virtual server configurations; fixes are in 14.1-66.59, 13.1-62.23 and 13.1-37.262.
Citrix NetScaler products confirmed to be under exploitation
Security researchers at watchTowr warn that multiple flaws are involved in the early stages of a hacking spree that could rival the 2023 CitrixBleed campaign.
Critical Citrix NetScaler memory flaw actively exploited in attacks
Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data.