Citrix demands immediate NetScaler patch for critical security vulnerabilities.
Mar 25, 2026 // 18:57 - Niko Dunn


Citrix addressed two security issues in its NetScaler ADC and NetScaler Gateway products. One of these flaws is quite similar to the CitrixBleed vulnerabilities that were previously exploited.

The serious flaw (CVE-2026-3055) is caused by inadequate checking of user-supplied data. This can lead to a memory issue on Citrix ADC or Gateway systems configured as a SAML identity provider (IDP). This could allow remote, unauthorized attackers to gain access to sensitive information, such as session tokens.

“Cloud Software Group strongly advises users of NetScaler ADC and NetScaler Gateway to promptly install the available updates,” the company stated in an announcement.

Citrix has also provided detailed instructions on how to find and fix NetScaler systems vulnerable to CVE-2026-3055.

The company also fixed the CVE-2026-4368 vulnerability, which affects appliances set up as Gateways (SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual servers. This can permit attackers with limited access to the system to trigger a race condition through simple attacks, potentially causing user sessions to be mixed up.

These two vulnerabilities affect NetScaler ADC and Gateway versions 13.1 and 14.1 (fixed in versions 13.1-62.23 and 14.1-66.59) and NetScaler ADC 13.1-FIPS and 13.1-NDcPP (fixed in version 13.1-37.262).

According to Shadowserver, an internet security monitoring organization, there are currently over 30,000 NetScaler ADC instances and more than 2,300 Gateway instances accessible online. However, it’s unknown how many have vulnerable configurations or have been updated to prevent attacks.

Since Citrix released patches for the vulnerability, multiple cybersecurity firms have stressed the importance of protecting NetScaler against CVE-2026-3055 attacks.

Many have also highlighted significant similarities to the CitrixBleed and CitrixBleed2 out-of-bounds memory-read issues that were exploited in zero-day attacks recently.

“Unfortunately, many people will find that this sounds similar to the widely exploited ‘CitrixBleed’ vulnerability from 2023 and its ‘CitrixBleed2’ variant disclosed in 2025, both of which were, and continue to be, actively used in real-world attacks,” cybersecurity firm watchTowr stated.

“Although Citrix says they found the vulnerability internally, it’s reasonable to expect that attackers will try to reverse engineer the patch to create exploits.”

“Exploitation of CVE-2026-3055 is likely to happen once exploit code is made public. Therefore, it is crucial for customers running affected Citrix systems to fix this vulnerability as quickly as possible. Citrix software has previously experienced memory leak vulnerabilities being widely exploited, including the infamous ‘CitrixBleed’ vulnerability, CVE-2023-4966, in 2023,” Rapid7 added.

In August 2025, CISA identified CitrixBleed2 as being actively exploited and gave federal agencies one day to protect their systems. In total, the U.S. cybersecurity agency has listed 21 Citrix vulnerabilities as exploited, with seven used in ransomware attacks.

#citrix  #critical  #demands.  #for  #immediate  #netscaler  #news  #patch  #security  #vulnerabilities   —   News