CVE-2026-3055Active Exploitation(citrix / netscaler_application_delivery_controller)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 62 mentions and remains active

Immediate actions

  • Patch citrix netscaler_application_delivery_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-02. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-125

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netscaler_application_delivery_controller
  • netscaler_gateway

Threat summary

  • Active exploitation appears in 145 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 399 mentions across 43 observed days

What's happening

  • Active exploitation reported across 145 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 25 signals
  • Patch or workaround mentioned in 153 signals
  • Technical details provided in 256 signals
  • General: 89 classified signals
  • Peaked 35d ago at 62 mentions (2026-03-30); latest day: 1
  • 399 total mentions across 43 days

Affected systems

Vendors
Products
netscaler_application_delivery_controllernetscaler_gateway

Deep dive

Activity timeline399 mentions / 43d
016314762Mentions · 2026-03-23: 17Mentions · 2026-03-24: 42Mentions · 2026-03-25: 21Mentions · 2026-03-26: 14Mentions · 2026-03-27: 11Mentions · 2026-03-28: 48Mentions · 2026-03-29: 43Mentions · 2026-03-30: 62Mentions · 2026-03-31: 42Mentions · 2026-04-01: 14Mentions · 2026-04-02: 10Mentions · 2026-04-03: 8Mentions · 2026-04-04: 5Mentions · 2026-04-05: 4Mentions · 2026-04-06: 2Mentions · 2026-04-07: 4Mentions · 2026-04-08: 4Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-14: 2Mentions · 2026-04-15: 6Mentions · 2026-04-16: 1Mentions · 2026-04-17: 4Mentions · 2026-04-18: 2Mentions · 2026-04-20: 3Mentions · 2026-04-21: 1Mentions · 2026-04-22: 2Mentions · 2026-05-06: 1Mentions · 2026-05-09: 5Mentions · 2026-05-11: 1Mentions · 2026-05-19: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 2Mentions · 2026-06-05: 1Mentions · 2026-06-08: 1Mentions · 2026-06-22: 1Mentions · 2026-07-02: 1Mentions · 2026-07-20: 2Mentions · 2026-07-30: 1Mentions · 2026-08-02: 2Mentions · 2026-08-16: 2Mentions · 2026-09-26: 1PoC Mentioned / Linked · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-28: 2PoC Mentioned / Linked · 2026-03-29: 6PoC Mentioned / Linked · 2026-03-30: 5PoC Mentioned / Linked · 2026-03-31: 4PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-06-04: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-03-28: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-06-04: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 3Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-27: 1Active Exploitation · 2026-03-28: 7Active Exploitation · 2026-03-29: 14Active Exploitation · 2026-03-30: 31Active Exploitation · 2026-03-31: 31Active Exploitation · 2026-04-01: 8Active Exploitation · 2026-04-02: 5Active Exploitation · 2026-04-03: 4Active Exploitation · 2026-04-04: 4Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-04-06: 2Active Exploitation · 2026-04-07: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-12: 1Active Exploitation · 2026-04-14: 2Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 3Active Exploitation · 2026-04-18: 2Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-05-09: 3Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-04: 2Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-08-02: 2Active Exploitation · 2026-08-16: 2Patch / Workaround · 2026-03-23: 8Patch / Workaround · 2026-03-24: 26Patch / Workaround · 2026-03-25: 7Patch / Workaround · 2026-03-26: 9Patch / Workaround · 2026-03-27: 6Patch / Workaround · 2026-03-28: 14Patch / Workaround · 2026-03-29: 13Patch / Workaround · 2026-03-30: 12Patch / Workaround · 2026-03-31: 18Patch / Workaround · 2026-04-01: 7Patch / Workaround · 2026-04-02: 4Patch / Workaround · 2026-04-03: 2Patch / Workaround · 2026-04-04: 3Patch / Workaround · 2026-04-05: 3Patch / Workaround · 2026-04-06: 2Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-06-04: 2Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-16: 2Technical Details · 2026-03-23: 13Technical Details · 2026-03-24: 28Technical Details · 2026-03-25: 13Technical Details · 2026-03-26: 4Technical Details · 2026-03-27: 8Technical Details · 2026-03-28: 42Technical Details · 2026-03-29: 27Technical Details · 2026-03-30: 38Technical Details · 2026-03-31: 27Technical Details · 2026-04-01: 8Technical Details · 2026-04-02: 5Technical Details · 2026-04-03: 4Technical Details · 2026-04-04: 1Technical Details · 2026-04-05: 3Technical Details · 2026-04-07: 3Technical Details · 2026-04-08: 3Technical Details · 2026-04-09: 2Technical Details · 2026-04-12: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 3Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 3Technical Details · 2026-04-20: 2Technical Details · 2026-04-22: 2Technical Details · 2026-05-09: 2Technical Details · 2026-05-19: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-02: 2Technical Details · 2026-08-16: 103-2303-2703-3104-0404-0804-1404-1805-0606-0306-2208-0209-26
Signal classification5 categories
Active Exploitation
13934.9%
Patch
9022.6%
General
8922.4%
Disclosure
7518.8%
PoC
51.3%
Referenced assets212 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-2317
Disclosure6General4Patch7
2026-03-2442
Active Exploitation3Disclosure10General6Patch23
2026-03-2521
Disclosure8General6Patch7
2026-03-2614
Active Exploitation1Disclosure3General2Patch8
2026-03-2711
Active Exploitation2Disclosure4General1Patch4
2026-03-2848
Active Exploitation7Disclosure15General16Patch9PoC1
2026-03-2943
Active Exploitation15Disclosure5General16Patch6PoC1
2026-03-3062
Active Exploitation31Disclosure6General20Patch4PoC1
2026-03-3142
Active Exploitation27Disclosure2General3Patch8PoC2
2026-04-0114
Active Exploitation8Disclosure1General2Patch3
2026-04-0210
Active Exploitation5Disclosure3Patch2
2026-04-038
Active Exploitation4Disclosure2General1Patch1
2026-04-045
Active Exploitation4General1
2026-04-054
Active Exploitation1Disclosure1Patch2
2026-04-062
Active Exploitation2
2026-04-074
Active Exploitation2General1Patch1
2026-04-084
Active Exploitation1Disclosure2General1
2026-04-092
Disclosure2
2026-04-101
Disclosure1
2026-04-121
Active Exploitation1
2026-04-142
Active Exploitation2
2026-04-156
Active Exploitation2Disclosure1General1Patch2
2026-04-161
Active Exploitation1
2026-04-174
Active Exploitation2General1Patch1
2026-04-182
Active Exploitation1Patch1
2026-04-203
Active Exploitation1Disclosure1General1
2026-04-211
General1
2026-04-222
Active Exploitation1Patch1
2026-05-061
Active Exploitation1
2026-05-095
Active Exploitation3General2
2026-05-111
General1
2026-05-191
Active Exploitation1
2026-06-031
Active Exploitation1
2026-06-042
Active Exploitation2
2026-06-051
Active Exploitation1
2026-06-081
Active Exploitation1
2026-06-221
General1
2026-07-021
General1
2026-07-202
Disclosure2
2026-07-301
Active Exploitation1
2026-08-022
Active Exploitation2
2026-08-162
Active Exploitation2
Full discourse20 posts
  • Rishi@rxerium
    Patch

    🚨 CVE-2026-3055 (CVSS 9.3), a unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances that could see active exploitation itw Vulnerability detection script available here: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-3055.yaml Patches are available as per Citrix's advisory: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300

    Post summary

    High‑severity memory overread flaw in Citrix NetScaler appliances is disclosed with detection script and patch available, with possible active exploitation in the wild.

    1065129114925.2K
    3.2K followersView on X
  • Sans Limite@SansLimit3
    General

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post advertises an AI‑driven attacker platform that automatically targets and validates listed CVEs, but provides no concrete PoC, exploit code, or evidence of active exploitation.

    837223619525.2K
    634 followersView on X
  • watchTowr@watchtowrcyber
    Patch

    watchTowr Intel is detecting active reconnaissance against NetScalers for CVE-2026-3055 through our Attacker Eye honeypot network. Exploitation is likely imminent. Patch now. watchTowr clients already have access to internal mechanisms to confidently identify their exposure. https://t.co/CZlXZ3Doy3

    Post summary

    The tweet announces CVE-2026-3055, warns of likely imminent exploitation, and urges patching, but provides no technical details or exploit evidence.

    03111214711.6K
    11.4K followersView on X
  • watchTowr@watchtowrcyber
    Disclosure

    Happy weekend! Enjoy our analysis of CVE-2026-3055 - yet another 'Memory Overread' vulnerability in Citrix NetScaler appliances. https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread

    Post summary

    The post announces an analysis of CVE-2026-3055, identifying it as a memory overread flaw in Citrix NetScaler appliances, but does not provide PoC code, exploit details, or patch information.

    238198359.3K
    11.4K followersView on X
  • watchTowr@watchtowrcyber
    General

    What number CitrixBleed are we on? Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one. Sigh. https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2

    Post summary

    The post refers to a detailed analysis of CitrixNetScaler CVE-2026-3055, highlighting a memory overread vulnerability but offering no PoC, exploit, patch, or active exploitation evidence.

    231093298.4K
    11.4K followersView on X
  • Defused@DefusedCyber
    Patch

    🚨 Update: Citrix just dropped a new security bulletin (CTX696300) with two fresh CVEs for NetScaler ADC & Gateway: CVE-2026-3055 - CVSS 9.3 Out-of-bounds read via insufficient input validation. Unauthenticated, network-accessible, low complexity. Requires SAML IDP configuration. Memory overread - same vulnerability class as CitrixBleed. CVE-2026-4368 - lower impact vuln also patched in the same bulletin. Tap into acute NetScaler intel before the mass exploiting starts! 👉 https://console.defusedcyber.com

    Post summary

    Citrix released bulletin CTX696300 addressing two NetScaler ADC & Gateway CVEs, including a high‑severity CVE‑2026‑3055 with an out‑of‑bounds read; both vulnerabilities have been patched in the bulletin.

    1335793046.4K
    6.3K followersView on X
  • The Hacker News@TheHackersNews
    General

    🚨 Attackers are probing Citrix NetScaler for CVE-2026-3055 (CVSS 9.3). Honeypots show requests to /cgi/GetAuthMethods to identify SAML IdP setups, which are required for exploitation. 🔗 How attackers are mapping vulnerable NetScaler targets → https://thehackernews.com/2026/03/citrix-netscaler-under-active-recon-for.html

    Post summary

    Attackers are probing Citrix NetScaler for CVE-2026-3055 by probing /cgi/GetAuthMethods, but no active exploitation, PoC, or patch information is reported.

    1315882116.6K
    1.2M followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨Citrix NetScaler CVE-2026-3055 is being actively exploited in the wild Attackers send crafted SAMLRequest payloads to /saml/login omitting the AssertionConsumerServiceURL field, triggering the appliance to leak memory contents via the NSC_TASS cookie. Our honeypot data shows exploitation activity from the same payload structure as the @watchtowrcyber PoC. Track exploitation of our Citrix honeypots 👉 https://console.defusedcyber.com/capabilities

    Post summary

    CVE-2026-3055 in Citrix NetScaler is actively exploited in the wild through crafted SAMLRequest payloads that trigger memory leaks, with honeypot data confirming ongoing activity that mirrors a known PoC by @watchtowrcyber.

    3264862521.0K
    6.7K followersView on X
  • watchTowr@watchtowrcyber
    General

    It's Monday! We are currently rapidly reacting to CVE-2026-3055 - yet another unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances. Active watchTowr Platform clients have been made aware of their exposure - reach out for support. https://t.co/nfGuPCrwL2

    Post summary

    The tweet informs clients that Citrix NetScaler ADC and Gateway appliances are exposed to CVE‑2026‑3055, an unauthenticated memory over‑read vulnerability, and urges them to seek support.

    024273277.9K
    11.1K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️We are now observing auth method fingerprinting activity against NetScaler ADC/Gateway in the wild. Attackers are probing /cgi/GetAuthMethods to enumerate enabled authentication flows in our Citrix honeypots. This is directly linked to CVE-2026-3055, which only impacts instances where ADC is configured as an IDP - this fingerprinting is likely identifying exactly that. If you’re running NetScaler as an IDP, patching is becoming pretty acute! Track Netscaler exploit attempts live 👉 https://console.defusedcyber.com/intel

    Post summary

    At least one observatory detects authentication enumeration against NetScaler ADC instances configured as an IDP, linked to CVE-2026-3055, indicating active exploitation in the wild and prompting urgent patching.

    0192712720.9K
    6.7K followersView on X
  • Rapid7@rapid7
    Disclosure

    🚨 On 3/23/26, #Citrix published a security advisory for a critical vuln. affecting #NetScaler ADC & Gateway products. CVE-2026-3055, an out-of-bounds read, allows unauthenticated remote attackers to leak information from the appliance's memory. Read on: https://r-7.co/41nwCJ7 https://t.co/pSovaJwOS3

    Post summary

    Citrix announced CVE-2026-3055, an out‑of‑bounds read that allows unauthenticated remote information leakage on NetScaler ADC & Gateway products; no PoC, exploit, or patch details were provided.

    126360156.7K
    123.9K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    ⚠️ Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation Source: https://cybersecuritynews.com/citrix-netscaler-instances-exploited/ Researchers warn of the in-the-wild exploitation of a recently disclosed critical vulnerability in Citrix NetScaler ADC and Gateway appliances. Active reconnaissance campaigns specifically targeting CVE-2026-3055, a high-severity memory overread flaw that could allow unauthenticated attackers to extract sensitive data. Organizations relying on affected Citrix instances are urged to apply patches immediately before the reconnaissance phase transitions into full-scale attack campaigns. Telemetry captured from honeypot networks shows threat actors actively utilizing POST requests to probe NetScaler appliances and uncover vulnerable authentication setups. #cybersecuritynews #citrix

    Post summary

    Researchers report real‑world exploitation of CVE‑2026‑3055 against Citrix NetScaler, with threat actors probing vulnerable appliances and urging organizations to patch immediately.

    41716593.5K
    53.1K followersView on X
  • Dark Web Informer@DarkWebInformer
    Patch

    ‼️ NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 CVE-2026-3055: Insufficient input validation leading to memory overread // 9.3 CVSS CVE-2026-4368: Race Condition leading to User Session Mixup // 7.7 CVSS CVE-2026-3055.yaml: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-3055.yaml Image/YAML Credit: @rxerium Citrix Advisory: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300 Citrix Blog: https://community.citrix.com/techzone-blogs/110_security-updates/critical-and-high-severity-updates-announced-for-netscaler-gateway-and-netscaler-adc-r1256/

    Post summary

    Citrix has issued an advisory for two CVEs affecting NetScaler ADC and Gateway, providing details of the vulnerabilities, a PoC, and links for patches.

    2121471710.1K
    180.1K followersView on X
  • Censys@censysio
    Patch

    🚨Critical vulnerability: CVE-2026-3055 is an unauthenticated out-of-bounds read in Citrix NetScaler ADC & Gateway (CVSS 9.3) 🔎 #CensysARC observes 173K exposed Web Properties ⚠️ No auth, no user interaction required (when SAML IDP is enabled) 🔴 Attackers could read sensitive memory contents 🛠️ Patches available — update immediately ▶️ Full advisory: https://hubs.ly/Q048vpmL0 #CVE20263055 #infosec

    Post summary

    CVE-2026-3055 is a critical 9.3 out‑of‑bounds read vulnerability in Citrix NetScaler that requires no authentication; patches are available and must be applied immediately.

    019037113.7K
    12.1K followersView on X
  • Simo@SimoKohonen
    General

    citrix netscaler CVE-2026-3055 exploitation is go 🚨

    Post summary

    The statement merely announces that exploitation of CVE-2026-3055 in Citrix Netscaler is ready, without providing evidence of active attacks, technical specifics, or a PoC link.

    160381510.2K
    3.1K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    Citrix Netscaler CVE-2026-3055 exploit statistics recorded since first exploit (27th March) 🍯 - 58 unique attacker IPs - 396 exploit events (one event can include multiple exploits as this is a memory leak vulnerability) Paths attempted as part of this exploit: /wsfed/passive?wctx /saml/login /wsfed/passive?wsctx /wsfed/passive /wsfed/passive?POLICY Exploiting continues heavy. Full intel available on https://console.defusedcyber.com/intel

    Post summary

    The post documents persistent exploitation of Citrix Netscaler CVE-2026-3055, presenting attacker counts, event statistics, and attack paths, and offers full intelligence via a linked dashboard.

    013030115.0K
    7.3K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Citrix NetScaler out-of-bounds read vulnerability CVE-2026-3055 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/p8x74NQJnf

    Post summary

    The tweet announces that CVE-2026-3055, an out-of-bounds read flaw in Citrix NetScaler, is listed in a Known Exploited Vulnerabilities Catalog, implying real‑world exploitation, but provides no PoC, patch, or technical attack details beyond the flaw type.

    11512625.2K
    298.7K followersView on X
  • watchTowr@watchtowrcyber
    General

    Rapid reaction gets you ahead. 6 days before CISA added CVE-2026-3055 to KEV, a Citrix NetScaler Memory Overread (CitrixBleed++) vulnerability, watchTowr clients were aware of their exposure. Reach out via our website if you need support. https://t.co/l1DlBil1tz

    Post summary

    The tweet notes that watchTowr clients were aware of the Citrix NetScaler memory overread vulnerability CVE-2026-3055 before it was added to the CISA KEV list, with no PoC, exploit, or mitigation details provided.

    1603422.9K
    12.1K followersView on X
  • NCSC UK@NCSC
    Disclosure

    The NCSC is encouraging UK organisations to take immediate action to mitigate two recently disclosed vulnerabilities, CVE-2026-3055 and CVE-2026-4368, that affect Citrix NetScaler ADC and Citrix NetScaler Gateway. Read more: https://www.ncsc.gov.uk/news/vulnerabilities-affecting-citrix-netscaler-adc-gateway

    Post summary

    The NCSC advisory prompts UK entities to address two newly disclosed Citrix NetScaler ADC and Gateway vulnerabilities without detailing patches or exploitation specifics.

    21402063.2K
    144.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-3055 reveals multiple memory overread bugs in Citrix NetScaler affecting /saml/login and /wsfed/passive endpoints. In-the-wild exploitation confirmed since March 27th, 2026. Technical details: • CVE-2026-3055 encompasses at least TWO distinct memory overread vulnerabilities • Second variant targets GET /wsfed/passive?wctx (missing = symbol triggers buffer overrun) • Leaked memory appears base64-encoded in NSC_TASS cookie responses • Only exploitable when NetScaler configured as SAML Identity Provider • Memory disclosure reveals HTTP headers, session IDs, and administrative tokens Attack methodology: • Simple GET request to /wsfed/passive?wctx (no value, no equals sign) • Vulnerable appliances return kilobytes of leaked memory content • Multiple requests yield different memory chunks each time • Administrative session hijacking possible via leaked session cookies DFIR artifacts: • Monitor for requests to /wsfed/passive?wctx and /saml/login endpoints • Large NSC_TASS cookie values (base64-encoded leaked memory) • 302 redirects with abnormally long Set-Cookie headers • Citrix-ns-orig-srcip headers in leaked memory indicate internal requests Hunt for GET requests to these endpoints without proper query parameters. Detection script and IOCs available in watchTowr Labs report. #DFIR_Radar

    Post summary

    The note reports confirmed in-the-wild exploitation of CVE-2026-3055 against Citrix NetScaler, with detailed memory‑overread exploitation via the /saml/login and /wsfed/passive endpoints and guidance for detection.

    2501361.6K
    1.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_application_delivery_controller---
Appcitrixnetscaler_gateway---

Explore more