Vulnerabilities & Exploits · Zero-Day Exploit

Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway affecting SAML IdP and Gateway/AAA configurations. One is an out‑of‑bounds memory read (CVE‑2026‑3055, CVSS 9.3) that can leak sensitive data.

10 sources · Mar 31

CVE-2026-3055

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 2

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

More from today