Full Report
Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data. [...]
Analysis Summary
# Vulnerability: Citrix NetScaler SAML/WS-Fed Memory Overread
## CVE Details
- CVE ID: CVE-2026-3055
- CVSS Score: Critical (Numerical score not explicitly provided in text, but categorized as "Critical Severity")
- CWE: CWE-125 (Out-of-bounds Read / Memory Overread)
## Affected Systems
- Products: Citrix NetScaler ADC and NetScaler Gateway
- Versions:
- Versions prior to 14.1-60.58
- Versions prior to 13.1-62.23 (13.1 branch)
- Versions prior to 13.1-37.262 (Long Term Service Release branch)
- Configurations: Appliances configured as a SAML Identity Provider (IdP) or using WS-Federation passive authentication.
## Vulnerability Description
CVE-2026-3055 consists of at least two distinct memory overread vulnerabilities. The first flaw resides in the `/saml/login` endpoint during the handling of SAML authentication. The second flaw affects the `/wsfed/passive` endpoint. Similar in nature to previous "CitrixBleed" vulnerabilities, these flaws allow an unauthenticated attacker to craft requests that trigger the appliance to leak contents of its memory. This leaked data can include sensitive information such as authenticated administrative session IDs.
## Exploitation
- Status: Exploited in the wild (Confirmed via honeypot activity as of March 27, 2026).
- Complexity: Low
- Attack Vector: Network (Remote)
## Impact
- Confidentiality: High (Leaking of session tokens and administrative credentials)
- Integrity: High (Potential for full appliance takeover via session hijacking)
- Availability: Medium (Potential for service disruption through administrative access)
## Remediation
### Patches
Citrix has released the following fixed versions:
- NetScaler ADC and NetScaler Gateway 14.1-60.58 and later
- NetScaler ADC and NetScaler Gateway 13.1-62.23 and later
- NetScaler ADC and NetScaler Gateway 13.1-37.262 and later
### Workarounds
No specific functional workarounds were provided other than updating the software. The vulnerability is restricted to on-premise appliances; Citrix-managed cloud services are generally not affected unless specified.
## Detection
- Indicators of Compromise: Monitor for anomalous GET/POST requests to `/saml/login` or `/wsfed/passive` originating from suspicious or unknown IP addresses.
- Detection methods and tools:
- Researchers at watchTowr have released a Python script to identify vulnerable hosts.
- Administrators should review logs for unauthorized administrative logins or session hijacking attempts.
- Monitor session activity for unusual administrative movements.
## References
- Citrix Security Bulletin: hxxps[://]support[.]citrix[.]com/support-home/kbsearch/article?articleNumber=CTX696300
- watchTowr Labs Analysis: hxxps[://]labs[.]watchtowr[.]com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/
- ShadowServer Statistics: hxxps[://]dashboard[.]shadowserver[.]org/statistics/iot-devices/time-series/?date_range=7&vendor=citrix&type=application-delivery-controller&model=netscaler&dataset=count&limit=100&group_by=geo&stacking=stacked