LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 30, 2026
CVSS 9.3 · Critical⚠ Actively exploited (CISA KEV)
9.3
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Apr 2, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on Mar 30, 2026, with a federal patch deadline of Apr 2, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

This vulnerability is an out-of-bounds read in Citrix NetScaler products when the appliance is configured as a SAML identity provider. The condition allows a memory overread that can expose portions of process memory to an attacker.

How it works

The weakness is classified as CWE-125, an out-of-bounds read. When the device operates as a SAML IDP, specially crafted input can cause the software to read past the intended buffer boundary, resulting in a memory overread. No further exploit mechanics are documented in the available summary.

Am I affected? How to find it in your systems

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway), and the FIPS and NDcPP variants are named in the summary. The issue is present only when the appliance is configured as a SAML IDP. Inventory all NetScaler instances in your environment, note which ones terminate SAML assertions or act as identity providers, and compare the installed software versions and configuration against the vendor advisory to determine exposure.

How to remediate

Apply mitigations per the vendor instructions provided in the advisory. Confirm the exact steps and any available updates against the official Citrix guidance rather than relying on secondary sources.

If you can't patch immediately

Follow applicable BOD 22-01 guidance for cloud services. Where mitigations cannot be applied, discontinue use of the affected configuration until a fix is in place. Network segmentation that limits exposure of the SAML IDP endpoints can reduce the attack surface while remediation is pending.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to data exposure. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCitrix · NetScaler
WeaknessCWE-125
CVSS base score9.3 (Critical)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedMar 23, 2026
Added to CISA KEVMar 30, 2026
Federal patch deadlineApr 2, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities