Critical NetScaler flaw: Citrix pushes urgent patch to stop unauthenticated data leaks.
Mar 24, 2026 // 10:38 - Tristan Wall


Citrix has issued security fixes for two vulnerabilities affecting NetScaler ADC and NetScaler Gateway. One critical vulnerability could allow an attacker to steal sensitive information from the application.

The security flaws include:

  • CVE-2026-3055 (CVSS score: 9.3) – Insufficient input checking leading to excessive memory reading
  • CVE-2026-4368 (CVSS score: 7.7) – A race condition that results in user session confusion

Rapid7, a cybersecurity firm, reported that CVE-2026-3055 is an out-of-bounds read issue that could enable remote, unauthenticated individuals to extract sensitive data from the device’s memory.

However, the Citrix ADC or Citrix Gateway must be configured as a SAML Identity Provider (SAML IDP) for the exploit to work. This means default configurations are not affected. Citrix advises customers to check their NetScaler Configuration for the string “add authentication samlIdPProfile .*” to see if the device is configured as a SAML IDP Profile.

CVE-2026-4368, on the other hand, requires that the appliance be configured as a gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an Authentication, Authorization, and Accounting (AAA) server. Customers should check the NetScaler Configuration to see if their devices are set up as any of the following:

  • AAA virtual server – add authentication vserver .*
  • Gateway – add vpn vserver .*

The vulnerabilities impact NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23, as well as NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. Users should apply the newest updates promptly to ensure optimal protection.

While there is no indication that these vulnerabilities have been actively exploited, threat actors have repeatedly targeted security flaws in NetScaler devices (CVE-2023-4966, also known as Citrix Bleed, CVE-2025-5777, also known as Citrix Bleed 2, CVE-2025-6543, and CVE-2025-7775), making it crucial for users to update their systems.

“CVE-2026-3055 allows unauthorized attackers to extract and read sensitive memory from NetScaler ADC deployments. If it sounds reminiscent, that’s because it is – this vulnerability is suspiciously similar to Citrix Bleed and Citrix Bleed 2, which continue to be a traumatic event for many,” said Benjamin Harris, CEO and founder of watchTowr, to The Hacker News.

“NetScalers are essential solutions that are consistently targeted for gaining initial access to enterprise environments. Although the advisory was just released, defenders need to respond quickly. Anyone running affected versions must update their systems immediately. Exploitation is highly likely.”

#citrix  #critical  #data  #flaw  #leaks.  #netscaler  #news  #patch  #pushes  #stop  #unauthenticated  #urgent   —   News