Citrix NetScaler SAML IDP - Memory Overread
CVE-2026-3055
Verified
Description
NetScaler ADC and NetScaler Gateway contain an insufficient input validation vulnerability when configured as a SAML IDP, leading to memory overread, letting attackers potentially access sensitive memory, exploit requires configuration as SAML IDP
Severity
Critical
Published Date
March 30, 2026
Template Author
watchtowr, shaikhyaser, dhiyaneshdk
CVE-2026-3055.yaml
9.5Severity
CVSS Metrics
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/
Remediation Steps
Update to the latest version with the fix for this vulnerability.