CVE-2026-4368Patch

MEDIUMCVSS 7.7 · HIGH

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 50 mentions across 13 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 27 signals
  • Technical details provided in 32 signals
  • Disclosure: 15 classified signals
  • General: 7 classified signals
  • Peaked 11d ago at 18 mentions (2026-03-24); latest day: 2
  • 50 total mentions across 13 days

Deep dive

Activity timeline50 mentions / 13d
0591418Mentions · 2026-03-23: 11Mentions · 2026-03-24: 18Mentions · 2026-03-25: 4Mentions · 2026-03-26: 5Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2Mentions · 2026-04-07: 1Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-04-17: 2PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-24: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-03-31: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-03-23: 6Patch / Workaround · 2026-03-24: 13Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-03-23: 7Technical Details · 2026-03-24: 12Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-17: 203-2303-2403-2503-2603-2703-2803-2903-3003-3104-0704-0804-0904-17
Signal classification5 categories
Patch
2244.0%
Disclosure
1530.0%
General
714.0%
Active Exploitation
510.0%
Discl.
12.0%
Referenced assets39 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-2311
Discl.1Disclosure5Patch5
2026-03-2418
Disclosure2General3Patch13
2026-03-254
Disclosure1Patch3
2026-03-265
Active Exploitation1Disclosure4
2026-03-271
General1
2026-03-281
Patch1
2026-03-291
General1
2026-03-302
Disclosure2
2026-03-312
Active Exploitation2
2026-04-071
General1
2026-04-081
Active Exploitation1
2026-04-091
Disclosure1
2026-04-172
Active Exploitation1General1
Full discourse20 posts
  • Defused@DefusedCyber
    Patch

    🚨 Update: Citrix just dropped a new security bulletin (CTX696300) with two fresh CVEs for NetScaler ADC & Gateway: CVE-2026-3055 - CVSS 9.3 Out-of-bounds read via insufficient input validation. Unauthenticated, network-accessible, low complexity. Requires SAML IDP configuration. Memory overread - same vulnerability class as CitrixBleed. CVE-2026-4368 - lower impact vuln also patched in the same bulletin. Tap into acute NetScaler intel before the mass exploiting starts! 👉 https://console.defusedcyber.com

    Post summary

    Citrix released bulletin CTX696300 announcing two new CVEs for NetScaler ADC & Gateway, including a high‑severity out‑of‑bounds read (CVE‑2026‑3055) that is already patched. No PoC, exploit code, or evidence of active exploitation is provided.

    1335793046.4K
    6.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 CVE-2026-3055: Insufficient input validation leading to memory overread // 9.3 CVSS CVE-2026-4368: Race Condition leading to User Session Mixup // 7.7 CVSS CVE-2026-3055.yaml: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-3055.yaml Image/YAML Credit: @rxerium Citrix Advisory: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300 Citrix Blog: https://community.citrix.com/techzone-blogs/110_security-updates/critical-and-high-severity-updates-announced-for-netscaler-gateway-and-netscaler-adc-r1256/

    Post summary

    The post announces the discovery of CVE-2026-3055 and CVE-2026-4368 in NetScaler ADC and Gateway, includes a PoC file reference, and URLs to the Citrix advisory and patch notes with technical details of the vulnerabilities.

    2121471710.1K
    180.1K followersView on X
  • NCSC UK@NCSC
    Patch

    The NCSC is encouraging UK organisations to take immediate action to mitigate two recently disclosed vulnerabilities, CVE-2026-3055 and CVE-2026-4368, that affect Citrix NetScaler ADC and Citrix NetScaler Gateway. Read more: https://www.ncsc.gov.uk/news/vulnerabilities-affecting-citrix-netscaler-adc-gateway

    Post summary

    The NCSC has issued a patch advisory urging immediate mitigation for CVE-2026-3055 and CVE-2026-4368 in Citrix NetScaler products, though the brief lacks explicit patch details.

    21402063.2K
    144.6K followersView on X
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2026-3055 (CVSS 9.3) & CVE-2026-4368 (CVSS 7.7) are critical/high vulnerabilities in Citrix NetScaler ADC/Gateway, involving memory overread and race conditions that could lead to session mixup. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJjaXRyaXgtTmV0U2NhbGVyLUdhdGV3YXkiIHx8IGFwcD0iY2l0cml4LUFEQyI= 🎯8k+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="citrix-NetScaler-Gateway" || app="citrix-ADC" 🔖Refer: https://thehackernews.com/2026/03/citrix-urges-patching-critical.html #OSINT #FOFA #CyberSecurity #Vulnerability #Citrix #NetScaler

    Post summary

    CVE-2026-3055 and CVE-2026-4368 are high‑severity issues in Citrix NetScaler involving memory overread and race conditions; Citrix urges users to apply the latest patches to mitigate the risk.

    0501471.6K
    13.7K followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300

    Post summary

    The message directs readers to a Citrix security bulletin covering CVE-2026-3055 and CVE-2026-4368, implying vendor guidance on addressing these issues.

    0501112.1K
    153.5K followersView on X
  • Defensorum@defensorum
    Disclosure

    🏥 #Healthcare organizations face ransomware threat from #NetScaler flaws 🚨 CVE-2026-3055 vulnerability scores CVSS 9.3 📊 CVE-2026-4368 race condition scores CVSS 7.7 📱 Remote access and VPN services at elevated risk 👉 https://www.defensorum.com/citrix-vulnerabilities-netscaler-adc-netscaler-gateway/ https://t.co/bFf5uCMSFZ

    Post summary

    The tweet announces two high‑scoring Citrix NetScaler vulnerabilities affecting healthcare, highlighting remote access and VPN risks but providing no PoC, exploit, or patch information.

    0404068
    29 followersView on X
  • Cytex@cytexsmb
    Patch

    Two vulnerabilities in Citrix NetScaler appliances could let unauthenticated attackers leak sensitive memory or hijack user sessions. The flaws echo past Citrix Bleed incidents, exploited aggressively once disclosed. CVE-2026-3055 (CVSS 9.3) Out-of-bounds read leads to memory overread. Unauthenticated attacker can leak sensitive appliance memory. Affects only appliances configured as SAML Identity Providers (SAML IDP). Default configurations are safe. CVE-2026-4368 (CVSS 7.7) Race condition leads to user session mixup. Affects appliances configured as gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA servers. Why It Matters NetScaler appliances are prime targets at the network edge. Previous memory leak flaws (Citrix Bleed) were weaponized at scale. No confirmed exploitation yet, but attackers move fast. What to Do Identify NetScaler ADC and Gateway instances. Check configuration: run add authentication samlIdPProfile .* for CVE-2026-3055; add authentication vserver . or add vpn vserver . for CVE-2026-4368. If affected, patch immediately to the latest fixed releases. Monitor for memory access anomalies or session irregularities. Past NetScaler flaws turned into widespread breaches. This window won't stay open long.

    Post summary

    The post announces two Citrix NetScaler CVEs, provides detailed technical information, highlights the lack of current exploitation, and urges immediate patching to mitigate the risks.

    11240182
    836 followersView on X
  • Qualys@qualys
    Disclosure

    Citrix has released a critical security advisory addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-3055 and CVE-2026-4368, these flaws allow for unauthenticated memory overread and user session mix-up- posing a significant risk to application availability and data integrity. Read the full technical breakdown here: https://bit.ly/4uKao1n #cybersecurity #vulnerabilitymanagement #threatintel

    Post summary

    Citrix released a critical advisory for CVE‑2026‑3055 and CVE‑2026‑4368, which allow unauthenticated memory overread and user session mix‑up in NetScaler ADC and Gateway.

    02032382
    34.2K followersView on X
  • Sami Laiho@samilaiho
    Disclosure

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 #CRITICAL https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368

    Post summary

    The content announces a Citrix security bulletin for two CVEs (CVE-2026-3055 and CVE-2026-4368) affecting NetScaler ADC and Gateway, labeling them as critical but providing no further technical or remediation details.

    01032890
    30.4K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    General

    🚨 ALERTĂ - Vulnerabilități de securitate în Citrix NetScaler ⚠️ Vulnerabilitățile CVE-2026-3055 și CVE-2026-4368 afectează soluțiile Citrix NetScaler, folosite de organizații pentru acces securizat la aplicații și resurse interne. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-de-securitate-in-citrix-netscaler #DNSC #Alert https://t.co/R3AwEYfkvR

    Post summary

    Alert posted about CVE‑2026‑3055 and CVE‑2026‑4368 affecting Citrix NetScaler solutions; a link to an article is provided, but no further technical or exploit details are given.

    03020195
    4.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    「NetScaler ADC/Gateway」に深刻な脆弱性 - 最新版へ更新を:Security NEXT https://www.security-next.com/182462 "Cloud Software Groupは現地時間2026年3月23日にセキュリティアドバイザリを公開し、2件の脆弱性「CVE-2026-3055」「CVE-2026-4368」について明らかにしたもの"

    Post summary

    The advisory identifies two critical CVEs in NetScaler ADC/Gateway and urges users to patch by updating to the latest release; no proof‑of‑concept or exploitation details are disclosed.

    10020221
    3.4K followersView on X
  • SOCRadar®@socradar
    Patch

    🚨 Critical #NetScaler flaws (CVE-2026-3055 & CVE-2026-4368) 🔹 Memory disclosure (CVSS 9.3) 🔹 Session mix-up risk 🔹 Impacts SAML, VPN, AAA setups Patch ASAP especially if internet-facing 🔍 Read more: https://hubs.la/Q0483VqJ0 #CyberSecurity #Infosec

    Post summary

    The post announces critical NetScaler vulnerabilities (CVE‑2026‑3055 and CVE‑2026‑4368) and emphasizes the need for immediate patching, providing technical details and a link for more information.

    00021291
    5.6K followersView on X
  • Thorsten E.@endi24
    Patch

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300

    Post summary

    Citrix has published a security bulletin for CVE-2026-3055 and CVE-2026-4368 affecting NetScaler ADC and Gateway, with the linked article likely containing patch or mitigation guidance.

    02001453
    4.6K followersView on X
  • Lupovis@LupovisDefence
    Disclosure

    🚨 Critical #Citrix #NetScaler Alert CVE-2026-3055 (CVSS 9.3)Out-of-bounds read lets unauthenticated attackers leak appliance memory, but only if configured as SAML IDP. Also patched: CVE-2026-4368 (session mix-up).

    Post summary

    The tweet announces CVE‑2026‑3055, an out‑of‑bounds read on Citrix NetScaler that can leak memory when set as a SAML IDP, while noting that a patch is already available for the related CVE‑2026‑4368.

    11010463
    552 followersView on X
  • Audrey Renée Bentley@BentleyAudrey
    General

    https://cybersec.picussecurity.com/s/cve-2026-3055-cve-2026-4368-inside-the-netscaler-citrixbleed-3-memory-overread-26789/1 CVE-2026-3055 & CVE-2026-4368: Inside the NetScaler "CitrixBleed 3" Memory Overread

    Post summary

    The content merely links to an article about CVE‑2026‑3055 and CVE‑2026‑4368, noting a memory overread in NetScaler, without providing PoC, exploitation, or mitigation details.

    00011455
    33.3K followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: CitrixBleed 3 - NetScaler ADC/Gateway memory overread + auth bypass (CVE-2026-3055, CVE-2026-4368) enables unauthenticated session hijack. 9 detections, 28 IOCs. https://intel.threadlinqs.com/#TL-2026-0384 #ThreatIntel #CyberSecurity #Citrix #NetScaler https://t.co/brVZEru9Bd

    Post summary

    The post announces that CVE‑2026‑3055 and CVE‑2026‑4368 are being actively exploited, with evidence of 9 detections and 28 IOCs, though no PoC or patch info is supplied.

    00020151
    80 followersView on X
  • TheDarkForge@DarkForgeNews
    Active Exploitation

    [CYBERSEC] 𝐂𝐕𝐄-𝟐𝟎𝟐𝟔-𝟑𝟎𝟓𝟓: 𝐂𝐢𝐭𝐫𝐢𝐱 𝐍𝐞𝐭𝐒𝐜𝐚𝐥𝐞𝐫 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝 𝐢𝐧 𝐭𝐡𝐞 𝐰𝐢𝐥𝐝, 𝐂𝐈𝐒𝐀 𝐢𝐬𝐬𝐮𝐞𝐬 𝐞𝐦𝐞𝐫𝐠𝐞𝐧𝐜𝐲 𝐝𝐢𝐫𝐞𝐜𝐭𝐢𝐯𝐞 A critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-3055, has been under active exploitation since at least March 27, 2026. Citrix disclosed the flaw on March 23 alongside a secondary race condition bug (CVE-2026-4368). Exploitation allows attackers to extract administrative session IDs, enabling potential full appliance takeover. Security firm watchTowr confirmed active exploitation via its honeypot network and noted the CVE actually covers two distinct bugs on the /saml/login endpoint. CISA ordered federal agencies to patch before Thursday. The flaw affects only on-premise appliances configured as SAML identity providers. Researchers have drawn parallels to CitrixBleed (2023) and CitrixBleed2 (2025). Affected versions include NetScaler ADC and Gateway before 14.1-60.58, 13.1-62.23, and 13.1-37.262.

    Post summary

    CVE-2026-3055 is actively exploited in the wild, prompting CISA to issue an emergency patch directive for affected Citrix NetScaler appliances.

    0002088
    24 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Citrix releases urgent fixes for CVE-2026-3055 (CVSS 9.3) and CVE-2026-4368 in NetScaler ADC and Gateway. https://www.redsecuretech.co.uk/blog/post/citrix-netscaler-critical-flaw-cve-2026-3055-patch-now/1017 #CyberSecurity #Citrix #NetScaler #CVE20263055 #PatchNow #CitrixBleed #InfoSec #Vulnerability #NetworkSecurity #OTSecurity https://t.co/pjUM9s4Aef

    Post summary

    Citrix has released urgent patch updates for CVE‑2026‑3055 and CVE‑2026‑4368 affecting NetScaler ADC and Gateway, urging immediate remediation.

    01010101
    42 followersView on X
  • Ferroque Systems Inc.@FerroqueSystems
    Patch

    A security vulnerability has been identified in NetScaler ADC & Gateway (CVE-2026-3055, CVE-2026-4368). Note: Updated builds may break STA bindings if using “/scripts/ctxsta.dll”. Workaround: bind FQDN/IP only. Validate before upgrading. https://ferrosys.co/41mvcP3 https://t.co/oGyY7Jv7Pn

    Post summary

    The text alerts users to CVE-2026-3055 and CVE-2026-4368 in NetScaler ADC & Gateway, advises applying a specific workaround, and recommends verification before upgrading.

    01010387
    178 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Citrix ❗ CVE-2026-4368 ❗ CVE-2026-3055 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-citrix-3/ https://t.co/cVGHHJvXTq

    Post summary

    The post simply lists two Citrix CVEs and provides URLs for additional information, without detailing technical aspects, exploits, or mitigation.

    0001094
    6.6K followersView on X

Explore more