CVE-2026-3055
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
- Published Mar 23, 2026
- CVSS 9.3 critical
- 4.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
Affected software
In the news
- CISA orders feds to patch exploited Citrix flaws by Wednesday BleepingComputer ·
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·
- Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway UK National Cyber Security Centre ·