CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-03-30. EPSS: 4% chance of exploitation in the next 30 days.
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Affected products
- Citrix NetScaler Application Delivery Controller: from 13.1, before 13.1-37.262 (fixed in 13.1-37.262); from 13.1, before 13.1-62.23 (fixed in 13.1-62.23); from 14.1, before 14.1-60.58 (fixed in 14.1-60.58)
- Citrix NetScaler Gateway: from 13.1, before 13.1-62.23 (fixed in 13.1-62.23); from 14.1, before 14.1-60.58 (fixed in 14.1-60.58)
Published 2026-03-23. Last modified 2026-06-17.