Vulnerabilities & Exploits · Zero-Day Exploit

Critical Citrix NetScaler Memory Leak Now Exploited; Admin Sessions at Risk

Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers are being actively exploited for an out‑of‑bounds memory read (CVE-2026-3055). Researchers at watchTowr and Defused observed exploitation from known threat actor IPs since March 27 and demonstrated leakage of authenticated administrative session IDs. The flaw affects NetScaler versions before 14.1-60.58, 13.1-62.23, and 13.1-37.262. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog and researchers say multiple memory overread issues may be involved.

10 sources · Mar 30

CVE-2026-3055

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 2

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-03-31

Every edition of this story: Critical Citrix NetScaler Memory Leak Now Exploited; Admin Sessions at Risk

More from today