Critical Citrix NetScaler Memory Leak Now Exploited; Admin Sessions at Risk
Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers are being actively exploited for an out‑of‑bounds memory read (CVE-2026-3055). Researchers at watchTowr and Defused observed exploitation from known threat actor IPs since March 27 and demonstrated leakage of authenticated administrative session IDs. The flaw affects NetScaler versions before 14.1-60.58, 13.1-62.23, and 13.1-37.262. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog and researchers say multiple memory overread issues may be involved.
Critical Citrix NetScaler memory flaw actively exploited in attacks
Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data.
Citrix NetScaler products confirmed to be under exploitation
Security researchers at watchTowr warn that multiple flaws are involved in the early stages of a hacking spree that could rival the 2023 CitrixBleed campaign.