Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up
Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway affecting SAML IdP and Gateway/AAA configurations. One is an out‑of‑bounds memory read (CVE‑2026‑3055, CVSS 9.3) that can leak sensitive data.
Citrix NetScaler products confirmed to be under exploitation
Security researchers at watchTowr warn that multiple flaws are involved in the early stages of a hacking spree that could rival the 2023 CitrixBleed campaign.
Critical Citrix NetScaler memory flaw actively exploited in attacks
Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data.