CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
How it works
The weakness is classified as CWE-125, an out-of-bounds read. When the device operates as a SAML IDP, specially crafted input can cause the software to read past the intended buffer boundary, resulting in a memory overread. No further exploit mechanics are documented in the available summary.
Am I affected? How to find it in your systems
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway), and the FIPS and NDcPP variants are named in the summary. The issue is present only when the appliance is configured as a SAML IDP. Inventory all NetScaler instances in your environment, note which ones terminate SAML assertions or act as identity providers, and compare the installed software versions and configuration against the vendor advisory to determine exposure.
- Check management interfaces and configuration files for SAML IDP settings.
- Review deployment locations such as perimeter gateways or internal application-delivery tiers.
- Examine logs for SAML-related request handling anomalies if telemetry is available.
How to remediate
Apply mitigations per the vendor instructions provided in the advisory. Confirm the exact steps and any available updates against the official Citrix guidance rather than relying on secondary sources.
If you can't patch immediately
Follow applicable BOD 22-01 guidance for cloud services. Where mitigations cannot be applied, discontinue use of the affected configuration until a fix is in place. Network segmentation that limits exposure of the SAML IDP endpoints can reduce the attack surface while remediation is pending.
If your data may have been exposed
Actively exploited vulnerabilities of this class can lead to data exposure. You can run a free exposure scan of your email addresses to check known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X