CVE-2026-3055
KEVCitrix NetScaler Out-of-Bounds Read Vulnerability
9.3
CriticalPublished:
Last updated:
Source:50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- Low
- Integrity (Subsequent)
- Low
- Availability (Subsequent)
- Low
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
References
50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300134c704f-9b21-4f2e-91b3-4a467353bcc0
https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/134c704f-9b21-4f2e-91b3-4a467353bcc0
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3055