CVE-2026-3055
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Mar 30, 2026
- US federal agencies must remediate it by Apr 2, 2026 (BOD 22-01)
- First attack observed 5 days after disclosure
- Confirmed by sensors, not only by reports
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 16, 2026 Sep 15, 2026 Sep 14, 2026 Sep 13, 2026 Sep 12, 2026 Sep 11, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| citrix | netscaler application delivery controller | < 13.1-37.262 |
| citrix | netscaler gateway | < 13.1-62.23 |
Related articles
AIAI Agent Orchestrated via Telegram Conducts Autonomous Attacks: Over 460 Targets Hit
Unit 42 found a Telegram-controlled AI agent using DeepSeek that autonomously attacked over 460 targets, exploiting CVEs in platforms like Langflow and n8n.
VulnerabilitiesCISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected
CISA adds three actively exploited vulnerabilities to the KEV catalog, impacting Langflow, Apache Tomcat, and N-central. Patch immediately by August 7, 2026.
VulnerabilitiesCitrix NetScaler: Exploitation Attempts Target Critical Vulnerability CVE-2026-19490
Attackers target CVE-2026-19490, a NetScaler ADC and Gateway auth bypass. PoC attempts seen from 3 countries. Patch vulnerable AAA, VPN configs now.
This product uses the NVD API but is not endorsed or certified by the NVD.