CISA ordered federal agencies to patch Citrix NetScaler appliances for CVE-2026-3055 by April 2. The flaw lets unauthenticated attackers steal admin SAML session IDs from NetScaler ADC and Gateway devices configured as SAML identity providers, which can enable full takeover of unpatched appliances. Citrix released fixes March 23 and researchers reported active exploitation days later; Shadowserver lists tens of thousands of NetScaler instances exposed online.
Part of the PlainSec briefing for 2026-04-01