CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup — Threadlinqs Intelligence
As of 2026-07-19, CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0294 · Severity: CRITICAL · CVSS: 9.3 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-19 · 2 updates · revalidated 2× · latest source
Attribution: N/A · UNKNOWN
Two critical vulnerabilities in Citrix NetScaler ADC and Gateway. CVE-2026-3055 (CVSS 9.3) is a pre-authentication memory overread via insufficient input validation when configured as SAML IDP,
Citrix has disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that pose significant risk to enterprise network infrastructure worldwide.
CVE-2026-3055 — Pre-Authentication Memory Overread (CVSS 9.3 Critical)
The most severe vulnerability, CVE-2026-3055, is a pre-authentication out-of-bounds read (CWE-125) affecting NetScaler ADC and Gateway appliances configured as SAML Identity Providers (SAML IDP). The vulnerability stems from insufficient input validation in the SAML IDP request processing path. When a NetScaler appliance processes SAML authentication requests, inadequate bounds checking allows a crafted request to cause the appliance to read memory beyond intended buffer boundaries. This enables unauthenticated remote attackers to extract sensitive data from appliance memory, including active session tokens, authentication state data, and potentially user credentials.
The vulnerability requires no authentication (PR:N), no user interaction (UI:N), and has low attack complexity (AC:L), making it highly exploitable. The attack surface is any NetScaler appliance with SAML IDP configured — detectable via the presence of 'add authentication samlIdPProfile' in the appliance configuration. Citrix-managed cloud instances and Adaptive Authentication deployments are NOT affected; only customer-managed instances are vulnerable.
CVE-2026-4368 — Race Condition Session Mixup (CVSS 7.7 High)
The second vulnerability, CVE-2026-4368, is a race condition (CWE-362) affecting NetScaler ADC and Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Under specific timing conditions during concurrent user authentication, the race condition causes one user's authenticated session context to be incorrectly associated with another user, enabling session hijacking and unauthorized access to another user's resources. This vulnerability only affects build 14.1-66.54 specifically and requires low privileges and precise timing to exploit.
Historical Context — The CitrixBleed Family
CVE-2026-3055 is the third major memory-read vulnerability in NetScaler's authentication infrastructure, following CitrixBleed (CVE-2023-4966, CVSS 9.4) in 2023 and CitrixBleed2 (CVE-2025-5777, CVSS 9.3) in 2025. Both predecessors saw rapid weaponization — CitrixBleed was exploited by LockBit and multiple APT groups, while CitrixBleed2 was exploited by Salt Typhoon against European telecom infrastructure with over 11.5 million attacks detected. The structural similarity to these predecessors makes rapid exploit development for CVE-2026-3055 highly likely.
Exposure and Impact
Shadowserver reports over 30,000 NetScaler ADC instances and 2,300+ Gateway instances exposed to the internet. Censys estimates approximately 40,000 total affected deployments, while Shodan shows over 56,000 discoverable Citrix NetScaler services. Exposed assets span critical sectors including industrials (22.6%), consumer discretionary (14.1%), financials, healthcare, and information technology.
Patch and Mitigation
Citrix has released patched versions: 14.1-66.59, 13.1-62.23, and 13.1-37.262 (FIPS/NDcPP). A known regression in builds 14.1-66.54 and 14.1-66.59 affects STA server binding when using full paths. Organizations must terminate all active sessions after patching, as leaked session tokens remain valid until explicitly invalidated. Interim mitigations include network-level IP allowlisting and deploying Global Deny List (GDL) signatures available for versions 14.1-60.52 and 14.1-60.57.
The vulnerability was discovered internally by Cloud Software Group through proactive security testing. As of March 28, 2026, no public proof-of-concept exploit exists and no active exploitation has been confirmed, but multiple security firms including Rapid7, Arctic Wolf, and watchTowr assess exploitation as imminent given the low attack complexity and established pattern of rapid weaponization of prior NetScaler vulnerabilities.
Weaknesses (CWE)
CWE-125, CWE-362, CWE-908
Target sectors: government, financial, healthcare, technology, industrials, telecommunications, energy, education, retail
Target regions: Global, North America, Europe, Asia Pacific, United Kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-3055, CVE-2026-4368, T1190, T1078, T1212, T1539, T1552, T1550, T1550, T1021, T1563, T1005