Critical Citrix NetScaler, Gateway Flaws Let Remote Attackers Leak Data
Key Takeaways Two new critical vulnerabilities (CVE-2026-3055 and CVE-2026-4368) have been discovered in Citrix NetScaler ADC and NetScaler Gateway appliances. These flaws could allow remote...
Key Takeaways
- Two new critical vulnerabilities (CVE-2026-3055 and CVE-2026-4368) have been discovered in Citrix NetScaler ADC and NetScaler Gateway appliances.
- These flaws could allow remote attackers to leak sensitive data or cause user session mixups, potentially exposing confidential information or granting unauthorized access.
- The most severe vulnerability, CVE-2026-3055, carries a CVSS score of 9.3 and affects appliances configured as a SAML Identity Provider.
- Admins are urged to apply the latest security patches immediately, as only customer-managed systems are affected.
Cloud Software Group has issued an urgent security alert regarding two significant vulnerabilities impacting self-managed NetScaler ADC and NetScaler Gateway devices. These critical flaws, identified as CVE-2026-3055 and CVE-2026-4368, could enable remote adversaries to extract sensitive data or trigger cross-user session confusion.
Table Of Content
Security professionals and network administrators are strongly advised to deploy the most recent security updates without delay to safeguard their networks against potential compromise.
Citrix NetScaler and Gateway Vulnerabilities Detailed
The security bulletin from Cloud Software Group details two distinct security issues, each affecting specific configurations of NetScaler appliances.
CVE-2026-3055: Critical Out-of-Bounds Read
The more severe of the two, CVE-2026-3055, is an out-of-bounds read vulnerability stemming from insufficient input validation. This flaw has been assigned a critical CVSS base score of 9.3. It allows remote attackers to induce a memory overread condition.
An out-of-bounds read permits an attacker to access memory locations beyond the intended boundaries of a buffer. This type of access can potentially expose critical operational data, user credentials, or active session tokens.
However, the exploitability of this vulnerability is conditional. It exclusively affects appliances configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP). Administrators can quickly ascertain their exposure by searching their NetScaler configuration for the specific string: add authentication samlIdPProfile .*.
CVE-2026-4368: User Session Mixup Race Condition
The second vulnerability, CVE-2026-4368, is a race condition that can lead to a user session mixup. Session mixups can inadvertently transfer an active session from one user to another, leading to the unintended exposure of sensitive information or unauthorized access to resources.
This issue arises when the appliance operates as a Gateway (encompassing SSL VPN, ICA Proxy, CVPN, and RDP Proxy functionalities) or as an Authentication, Authorization, and Auditing (AAA) virtual server.
Deployments are considered exposed if their configuration files contain either add authentication vserver .* or add vpn vserver .*. It is crucial to note that these vulnerabilities exclusively affect customer-managed NetScaler ADC and Gateway systems.
Cloud environments leveraging Citrix-managed cloud services or Citrix-managed Adaptive Authentication are not impacted, as Cloud Software Group has already implemented the necessary infrastructure updates for these services.
These vulnerabilities were identified through internal security reviews conducted by Cloud Software Group. At present, there is no evidence of active exploitation in the wild.
Nevertheless, the critical nature of the memory overread vulnerability, coupled with the potential for session integrity breaches, necessitates immediate patching and diligent monitoring of network activity.
What You Should Do
- Immediately upgrade affected NetScaler ADC and Gateway appliances to the latest supported firmware versions as per the vendor’s security bulletin.
- Verify your appliance configurations for SAML IdP (
add authentication samlIdPProfile .*) and Gateway/AAA virtual server (add authentication vserver .*oradd vpn vserver .*) settings to determine your specific exposure. - Monitor network logs and authentication systems for any unusual activity, unauthorized access attempts, or signs of session hijacking.
- Regularly review and update security policies related to authentication and access control for all NetScaler deployments.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.