CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup
CVE-2026-3055 & CVE-2026-4368 (TL-2026-0294) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-03-28 and last reviewed 2026-07-19. It has no confirmed attribution, affects Citrix / Cloud Software Group NetScaler ADC, references 2 CVEs (CVE-2026-3055, CVE-2026-4368), maps to 25 MITRE ATT&CK techniques (T1005, T1020, T1021), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-0294
- Threat ID
- TL-2026-0294
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-03-28
- Last reviewed
- 2026-07-19
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, industrials, telecommunications, energy, education, retail
- Target regions
- Global, North America, Europe, Asia Pacific, United Kingdom
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-07-19 · 2 updates · revalidated 2× · latest source
Two critical vulnerabilities in Citrix NetScaler ADC and Gateway. CVE-2026-3055 (CVSS 9.3) is a pre-authentication memory overread via insufficient input validation when configured as SAML IDP, enabling unauthenticated remote attackers to read sensitive memory including session tokens and credentials. CVE-2026-4368 (CVSS 7.7) is a race condition causing user session mixup when configured as Gateway or AAA virtual server. NCSC and CERT-EU have urged immediate patching. Over 30,000 instances exposed globally.
How CVE-2026-3055 & CVE-2026-4368 works
Citrix has disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that pose significant risk to enterprise network infrastructure worldwide.
CVE-2026-3055 — Pre-Authentication Memory Overread (CVSS 9.3 Critical)
The most severe vulnerability, CVE-2026-3055, is a pre-authentication out-of-bounds read (CWE-125) affecting NetScaler ADC and Gateway appliances configured as SAML Identity Providers (SAML IDP). The vulnerability stems from insufficient input validation in the SAML IDP request processing path. When a NetScaler appliance processes SAML authentication requests, inadequate bounds checking allows a crafted request to cause the appliance to read memory beyond intended buffer boundaries. This enables unauthenticated remote attackers to extract sensitive data from appliance memory, including active session tokens, authentication state data, and potentially user credentials.
The vulnerability requires no authentication (PR:N), no user interaction (UI:N), and has low attack complexity (AC:L), making it highly exploitable. The attack surface is any NetScaler appliance with SAML IDP configured — detectable via the presence of 'add authentication samlIdPProfile' in the appliance configuration. Citrix-managed cloud instances and Adaptive Authentication deployments are NOT affected; only customer-managed instances are vulnerable.
CVE-2026-4368 — Race Condition Session Mixup (CVSS 7.7 High)
The second vulnerability, CVE-2026-4368, is a race condition (CWE-362) affecting NetScaler ADC and Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Under specific timing conditions during concurrent user authentication, the race condition causes one user's authenticated session context to be incorrectly associated with another user, enabling session hijacking and unauthorized access to another user's resources. This vulnerability only affects build 14.1-66.54 specifically and requires low privileges and precise timing to exploit.
Historical Context — The CitrixBleed Family
CVE-2026-3055 is the third major memory-read vulnerability in NetScaler's authentication infrastructure, following CitrixBleed (CVE-2023-4966, CVSS 9.4) in 2023 and CitrixBleed2 (CVE-2025-5777, CVSS 9.3) in 2025. Both predecessors saw rapid weaponization — CitrixBleed was exploited by LockBit and multiple APT groups, while CitrixBleed2 was exploited by Salt Typhoon against European telecom infrastructure with over 11.5 million attacks detected. The structural similarity to these predecessors makes rapid exploit development for CVE-2026-3055 highly likely.
Exposure and Impact
Shadowserver reports over 30,000 NetScaler ADC instances and 2,300+ Gateway instances exposed to the internet. Censys estimates approximately 40,000 total affected deployments, while Shodan shows over 56,000 discoverable Citrix NetScaler services. Exposed assets span critical sectors including industrials (22.6%), consumer discretionary (14.1%), financials, healthcare, and information technology.
Patch and Mitigation
Citrix has released patched versions: 14.1-66.59, 13.1-62.23, and 13.1-37.262 (FIPS/NDcPP). A known regression in builds 14.1-66.54 and 14.1-66.59 affects STA server binding when using full paths. Organizations must terminate all active sessions after patching, as leaked session tokens remain valid until explicitly invalidated. Interim mitigations include network-level IP allowlisting and deploying Global Deny List (GDL) signatures available for versions 14.1-60.52 and 14.1-60.57.
The vulnerability was discovered internally by Cloud Software Group through proactive security testing. As of March 28, 2026, no public proof-of-concept exploit exists and no active exploitation has been confirmed, but multiple security firms including Rapid7, Arctic Wolf, and watchTowr assess exploitation as imminent given the low attack complexity and established pattern of rapid weaponization of prior NetScaler vulnerabilities.
MITRE ATT&CK techniques used in TL-2026-0294
collection
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
lateral-movement
T1021 Remote Services; T1550 Use Alternate Authentication Material; T1563 Remote Service Session Hijacking
Credential Access
T1040 Network Sniffing; T1187 Forced Authentication; T1528 Steal Application Access Token; T1606 Forge Web Credentials
Discovery
T1046 Network Service Discovery; T1518 Software Discovery
defense-evasion
Initial Access
T1133 External Remote Services
initial-access
T1190 Exploit Public-Facing Application
credential-access
T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Collection
T1213 Data from Information Repositories
Impact
Resource Development
resource-development
Reconnaissance
T1590 Gather Victim Network Information; T1592 Gather Victim Host Information
reconnaissance
Affected products and versions in CVE-2026-3055 & CVE-2026-4368
- Citrix / Cloud Software Group — NetScaler ADC
Vulnerable versions: 14.1 before 14.1-66.59; 13.1 before 13.1-62.23
Fixed in: 14.1-66.59; 13.1-62.23 - Citrix / Cloud Software Group — NetScaler Gateway
Vulnerable versions: 14.1 before 14.1-66.59; 13.1 before 13.1-62.23
Fixed in: 14.1-66.59; 13.1-62.23 - Citrix / Cloud Software Group — NetScaler ADC FIPS
Vulnerable versions: 13.1-FIPS before 13.1-37.262
Fixed in: 13.1-37.262 - Citrix / Cloud Software Group — NetScaler ADC NDcPP
Vulnerable versions: 13.1-NDcPP before 13.1-37.262
Fixed in: 13.1-37.262
Remediation for CVE-2026-3055 & CVE-2026-4368
Patches
- NetScaler ADC/Gateway 14.1: Update to 14.1-66.59 or later
- NetScaler ADC/Gateway 13.1: Update to 13.1-62.23 or later
- NetScaler ADC 13.1-FIPS: Update to 13.1-37.262 or later
- NetScaler ADC 13.1-NDcPP: Update to 13.1-37.262 or later
Immediate actions
- Apply Citrix patches immediately: 14.1-66.59, 13.1-62.23, or 13.1-37.262 (FIPS/NDcPP)
- Terminate all active user sessions after patching to invalidate potentially leaked session tokens
- Create appliance snapshots before patching for forensic preservation
- Deploy Global Deny List (GDL) signatures for versions 14.1-60.52 and 14.1-60.57 as interim mitigation
- Implement network-level IP allowlisting to restrict access to NetScaler management and SAML endpoints
Workarounds
- If patching is not immediately possible, restrict network access to SAML IDP endpoints via IP allowlisting
- Deploy GDL signatures as interim protection (no reboot required)
- Disable SAML IDP configuration if not actively required
- Monitor ns.log for anomalous SAML authentication patterns
Longer-term hardening
- Audit NetScaler configurations for SAML IDP profiles (search for 'add authentication samlIdPProfile')
- Audit for Gateway/AAA virtual server configurations (search for 'add authentication vserver' or 'add vpn vserver')
- Deploy network segmentation to limit lateral movement from compromised edge devices
- Implement continuous vulnerability scanning with Qualys QIDs 386883 and 386882
- Establish monitoring for anomalous SAML authentication requests and session behavior
- Review and harden all internet-facing NetScaler deployments
- Consider migration to Citrix-managed cloud instances which are not affected
CVEs associated with CVE-2026-3055 & CVE-2026-4368
Weaknesses (CWE) in CVE-2026-3055 & CVE-2026-4368
CWE-125, CWE-362, CWE-908
Timeline of CVE-2026-3055 & CVE-2026-4368
Showing the 20 most recent tracked events.
- Citrix publishes security bulletin CTX696300 disclosing CVE-2026-3055 and CVE-2026-4368 affecting NetScaler ADC and Gateway
- UK NCSC publishes advisory urging organizations to take immediate action on Citrix NetScaler vulnerabilities
- Qualys releases QIDs 386883 (CVE-2026-3055) and 386882 (CVE-2026-4368) for vulnerability detection; Rapid7 InsightVM checks available
- Rapid7, Arctic Wolf, Help Net Security, and multiple security firms publish emergency threat advisories warning exploitation is imminent
- NVD publishes CVE entries for CVE-2026-3055 (CVSS 9.3) and CVE-2026-4368 (CVSS 7.7), status Awaiting Analysis
- CyberNews reports nearly 40,000 Citrix NetScaler instances exposed to the internet; Shadowserver reports 30,000+ NetScaler ADC instances
- CERT-EU publishes security advisory 2026-003 confirming no public evidence of active exploitation but recommending immediate patching
- Rapid7 ships authenticated vulnerability checks for CVE-2026-3055 in InsightVM, Nexpose, and Exposure Command.
- CrowdSec telemetry records the start of mass probing for CVE-2026-3055, eventually totaling 40+ source IPs, majority hosted on AWS (AS16509).
- Independent researchers (Defused Cyber) observe authentication-method fingerprinting via /cgi/GetAuthMethods against NetScaler honeypots.
- watchTowr Labs' honeypot network observes active in-the-wild exploitation of CVE-2026-3055 from known threat-actor source IPs, prior to public technical root-cause disclosure.
- NCSC CTO weekly summary reiterates urgency for UK organisations to patch CVE-2026-3055 and CVE-2026-4368 immediately
- watchTowr Labs publishes 'Part 2' detailing the /wsfed/passive?wctx memory-overread variant exploited via the NSC_TASS response cookie.
- CISA adds CVE-2026-3055 to the Known Exploited Vulnerabilities (KEV) catalog on confirmed active-exploitation evidence, federal patch deadline 2026-04-02.
- Threat-modeling.com reports large-scale exploitation of CVE-2026-3055 corroborated by Fortinet telemetry.
- A public Metasploit exploitation module for CVE-2026-3055 becomes available, lowering the barrier to mass exploitation.
- Picus Security publishes joint analysis of CVE-2026-3055 and CVE-2026-4368, dubbing the pair 'CitrixBleed 3' and adding a simulation module (Threat ID 67234) to its threat library.
- CISA BOD 22-01 federal patch deadline for CVE-2026-3055 remediation on FCEB agency systems.
- As of 2026-05-29, this "CitrixBleed 3" NetScaler memory overread (CVE-2026-3055) is actively exploited: CISA added it to KEV on 2026-03-30 (patch-by 04-02), a public Metasploit module exists, and in-the-wild SAML-IDP attacks leak session tokens. Patches shipped but tens of thousands of instances stay exposed, so the record's PATCHED/theoretical status is outdated.
- NVD entry for CVE-2026-3055 last modified, reflecting refined CVSS scoring and reference set.
Update history for TL-2026-0294
- 2026-07-19 — CVE-2026-3055: Citrix NetScaler ADC/Gateway SAML Memory Overread — Actively Exploited, Added to CISA KEV: What changed No severity/exploitability/status escalation needed — the existing record was already revalidated to CRITICAL/ACTIVE/ACTIVE with CVSS 9.3. This report corroborates that assessment with independent Fortinet/Picus/Horizon3 confir
- 2026-07-19 — CVE-2026-3055: Citrix NetScaler ADC/Gateway Memory Overread — Active Exploitation via SAML/WS-Fed Endpoints: What changed Exploitability THEORETICAL → ACTIVE: watchTowr Labs honeypots observed in-the-wild exploitation beginning 2026-03-27, CISA added the CVE to KEV on 2026-03-30, and a public Metasploit module shipped 2026-03-31 — confirming the r
Sources cited for CVE-2026-3055 & CVE-2026-4368
- Citrix Security Bulletin CTX696300
- NCSC CTO Weekly Summary - Week Ending March 29th 2026
- NVD - CVE-2026-3055
- NVD - CVE-2026-4368
- NCSC UK Advisory - Vulnerabilities Affecting Citrix NetScaler ADC and Gateway
- CERT-EU Security Advisory 2026-003
- Rapid7 ETR: CVE-2026-3055 Citrix NetScaler ADC and Gateway Out-of-Bounds Read
- Arctic Wolf: CVE-2026-3055 Critical NetScaler Vulnerability
- Help Net Security: Critical NetScaler Flaw Could Leak Sensitive Data
- CSO Online: New Critical Citrix NetScaler Hole of Similar Severity to CitrixBleed2
- CyCognito: Citrix NetScaler ADC and Gateway Vulnerabilities
- Qualys ThreatPROTECT: Citrix NetScaler Multiple Vulnerabilities
- The Hacker News: Citrix Urges Patching Critical NetScaler Vulnerability
- BleepingComputer: Citrix Urges Admins to Patch NetScaler Flaws
- SecurityWeek: Critical Citrix NetScaler Vulnerability Poised for Exploitation
Threats related to CVE-2026-3055 & CVE-2026-4368
- CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Unauthenticated Memory Disclosure and Session Hijacking
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure
- CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of Disclosure
- CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with Accompanying CVE-2026-19489 Memory Overflow (CVSS 8.8)
Detection coverage for TL-2026-0294
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0294 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.