Vulnerabilities & Exploits · Zero-Day Exploit

Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

Citrix released patches for two NetScaler ADC and Gateway vulnerabilities, CVE-2026-3055 and CVE-2026-4368. CVE-2026-3055 is an out-of-bounds read (CVSS 9.3) that can let unauthenticated attackers leak appliance memory when configured as a SAML Identity Provider. CVE-2026-4368 is a race condition (CVSS 7.7) that can cause user session mix-ups on Gateway or AAA virtual server configurations; fixes are in 14.1-66.59, 13.1-62.23 and 13.1-37.262.

10 sources · Mar 31

CVE-2026-3055

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 2

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-03-25

Every edition of this story: Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

More from today