🔴 CVE-2026-3055

Critical memory overread vulnerability in NetScaler ADC and Gateway when configured as SAML IDP. Actively exploited in the wild with CISA KEV listing, directly exploitable over the network without authentication.

← Back to Overview
HIGH_RISK
Risk Level
9.3
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-03-23

Added to CISA KEV: 2026-03-30 7 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-03-31)

The CVE-2026-3055 vulnerability affects Citrix NetScaler ADC and NetScaler Gateway, which are often configured as internet-facing authentication devices [1][5].

Evidence of Active Exploitation:
  • Yes, there is evidence of active exploitation in the wild [6][7].
  • CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog [3][7]. This catalog is maintained by CISA as an authoritative source of vulnerabilities that have been exploited in real-world attacks [3].
  • The active exploitation has been ongoing since at least March 27, 2026 [2].
Attack Vectors and Exploitation Methods:
  • The vulnerability is described as an "Out-of-Bounds Read" due to insufficient input validation [4][5].
  • Threat actors frequently target internet-facing authentication devices like NetScaler to establish an initial foothold into enterprise networks [1].
  • While it is currently unknown if the flaw is being utilized in ransomware campaigns, the active exploitation of edge gateway appliances is considered a severe threat [1].
Use in Targeted Attacks:
  • The provided information confirms active exploitation in the wild and that threat actors are leveraging this vulnerability in real-world attacks [1][7]. However, specific details about whether it has been used in targeted attacks against particular organizations are not explicitly mentioned in the provided sources.
CISA Known Exploited Vulnerabilities (KEV) Status:
  • CVE-2026-3055 is listed in CISA's Known Exploited Vulnerabilities Catalog [7][8].
  • CISA has mandated a highly accelerated remediation timeline for this specific threat [1].
Technical Details about Internet Exploitability:
  • The vulnerability is a critical flaw affecting Citrix NetScaler ADC and Gateway products [5][6].
  • It has a CVSS score of 9.3, indicating a high severity [2].
  • The technical root cause is insufficient input validation leading to a memory overread [4].
  • The vulnerability is particularly risky when NetScaler is configured as a SAML Identity Provider [2].

Sources

  1. CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in...

    By adding CVE-2026-3055 to the KEV catalog, CISA confirms that threat actors are actively leveraging this vulnerability in real-world attacks. While the agency notes that it is currently unknown if the flaw is being utilized in ransomware campaigns, the active exploitation of any edge gateway applia…

  2. Urgent Security Alert: Critical Citrix Vulnerability CVE-2026-3055 ...

    Spread the loveIn a concerning development for the cybersecurity landscape, a critical vulnerability affecting Citrix NetScaler ADC and Gateway, identified as CVE-2026-3055, has been under active exploitation since March 27, 2026. This flaw, rated with a CVSS score of 9.3, poses significant risks to…

  3. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…

  4. CVE-2026-3055 - Insufficient input validation leading to memory overread

    Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-3055 weaknesses.EPSS is a daily estimate of the probability of exploitation activity being observed over…

  5. CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out ...

    On March 23, 2026, Citrix published a security advisory for a critical vulnerability affecting their NetScaler ADC and NetScaler Gateway ...