Citrix NetScaler CVE-2026-3055: Two Memory Overread Bugs, One CVE, Active Exploitation
Last Wednesday I woke up to three Slack messages from different clients, all asking the same thing: "Is our NetScaler safe?" A new Citrix vulnerability had dropped — CVE-2026-3055 — and by Saturday...

Source: DEV Community
Last Wednesday I woke up to three Slack messages from different clients, all asking the same thing: "Is our NetScaler safe?" A new Citrix vulnerability had dropped — CVE-2026-3055 — and by Saturday, CISA had already added it to the Known Exploited Vulnerabilities catalog. That's a 7-day turnaround from disclosure to confirmed in-the-wild exploitation. If you're running NetScaler ADC or NetScaler Gateway with SAML configured, stop what you're doing and patch. What CVE-2026-3055 Actually Does CVE-2026-3055 is an out-of-bounds memory read in Citrix NetScaler ADC and NetScaler Gateway. CVSS 9.3. An unauthenticated attacker sends a crafted request to your SAML endpoint, and your appliance responds by dumping chunks of its memory — including admin session tokens. If that sounds familiar, it should. This is the same class of bug that plagued CitrixBleed (CVE-2023-4966) — one of the most exploited vulnerabilities of 2023. The security community is already calling this one "CitrixBleed 3.0," an