Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: Medusa Ransomware Steals Data, Disables Security, Encrypts Networks
August 18, 2026
WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
August 18, 2026
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
Home/CyberSecurity News/Critical Citrix NetScaler, Gateway Flaws Let Remote Attackers Leak Data
CyberSecurity News

Critical Citrix NetScaler, Gateway Flaws Let Remote Attackers Leak Data

Key Takeaways Two new critical vulnerabilities (CVE-2026-3055 and CVE-2026-4368) have been discovered in Citrix NetScaler ADC and NetScaler Gateway appliances. These flaws could allow remote...

Sarah simpson
Sarah simpson
March 27, 2026 3 Min Read
66 0

Key Takeaways

  • Two new critical vulnerabilities (CVE-2026-3055 and CVE-2026-4368) have been discovered in Citrix NetScaler ADC and NetScaler Gateway appliances.
  • These flaws could allow remote attackers to leak sensitive data or cause user session mixups, potentially exposing confidential information or granting unauthorized access.
  • The most severe vulnerability, CVE-2026-3055, carries a CVSS score of 9.3 and affects appliances configured as a SAML Identity Provider.
  • Admins are urged to apply the latest security patches immediately, as only customer-managed systems are affected.

Cloud Software Group has issued an urgent security alert regarding two significant vulnerabilities impacting self-managed NetScaler ADC and NetScaler Gateway devices. These critical flaws, identified as CVE-2026-3055 and CVE-2026-4368, could enable remote adversaries to extract sensitive data or trigger cross-user session confusion.

Table Of Content

  • Key Takeaways
  • Citrix NetScaler and Gateway Vulnerabilities Detailed
  • CVE-2026-3055: Critical Out-of-Bounds Read
  • CVE-2026-4368: User Session Mixup Race Condition
  • What You Should Do

Security professionals and network administrators are strongly advised to deploy the most recent security updates without delay to safeguard their networks against potential compromise.

Citrix NetScaler and Gateway Vulnerabilities Detailed

The security bulletin from Cloud Software Group details two distinct security issues, each affecting specific configurations of NetScaler appliances.

CVE-2026-3055: Critical Out-of-Bounds Read

The more severe of the two, CVE-2026-3055, is an out-of-bounds read vulnerability stemming from insufficient input validation. This flaw has been assigned a critical CVSS base score of 9.3. It allows remote attackers to induce a memory overread condition.

An out-of-bounds read permits an attacker to access memory locations beyond the intended boundaries of a buffer. This type of access can potentially expose critical operational data, user credentials, or active session tokens.

However, the exploitability of this vulnerability is conditional. It exclusively affects appliances configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP). Administrators can quickly ascertain their exposure by searching their NetScaler configuration for the specific string: add authentication samlIdPProfile .*.

CVE-2026-4368: User Session Mixup Race Condition

The second vulnerability, CVE-2026-4368, is a race condition that can lead to a user session mixup. Session mixups can inadvertently transfer an active session from one user to another, leading to the unintended exposure of sensitive information or unauthorized access to resources.

This issue arises when the appliance operates as a Gateway (encompassing SSL VPN, ICA Proxy, CVPN, and RDP Proxy functionalities) or as an Authentication, Authorization, and Auditing (AAA) virtual server.

Deployments are considered exposed if their configuration files contain either add authentication vserver .* or add vpn vserver .*. It is crucial to note that these vulnerabilities exclusively affect customer-managed NetScaler ADC and Gateway systems.

Cloud environments leveraging Citrix-managed cloud services or Citrix-managed Adaptive Authentication are not impacted, as Cloud Software Group has already implemented the necessary infrastructure updates for these services.

These vulnerabilities were identified through internal security reviews conducted by Cloud Software Group. At present, there is no evidence of active exploitation in the wild.

Nevertheless, the critical nature of the memory overread vulnerability, coupled with the potential for session integrity breaches, necessitates immediate patching and diligent monitoring of network activity.

What You Should Do

  • Immediately upgrade affected NetScaler ADC and Gateway appliances to the latest supported firmware versions as per the vendor’s security bulletin.
  • Verify your appliance configurations for SAML IdP (add authentication samlIdPProfile .*) and Gateway/AAA virtual server (add authentication vserver .* or add vpn vserver .*) settings to determine your specific exposure.
  • Monitor network logs and authentication systems for any unusual activity, unauthorized access attempts, or signs of session hijacking.
  • Regularly review and update security policies related to authentication and access control for all NetScaler deployments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer on macOS

Next Post

Critical Red Hat Polkit Flaw (CVE-2021-3560) Lets Attackers Gain Root Privileges

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
JWR Phishing Framework Steals Banking Credentials via WebSocket Control
August 18, 2026
GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan
August 18, 2026
BTMob Fraud-as-a-Service Platform Uses 1,400 Servers for Android Takeovers
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us