Vulnerabilities & Exploits · Zero-Day Exploit

Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

The bug is a memory overread (CVSS 9.3) that can leak data on SAML IDP-configured appliances. Probes target /cgi/GetAuthMethods to fingerprint flows; affected 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23.

10 sources · Mar 31

CVE-2026-3055

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 2

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: Citrix NetScaler Flaws Risk Memory Disclosure and Session Mix‑up

More from today