CVE-2026-3055

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

  • Published Mar 23, 2026
  • CVSS 9.3 critical
  • 4.0% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • Public exploit code is available

Affected software

In the news

CVE-2026-3055 at the National Vulnerability Database