Critical Citrix NetScaler flaw gets official patch warning from CISA



  • CISA adds Citrix CVE‑2026‑3055 to Known Exploited Vulnerabilities catalog, confirming in‑the‑wild abuse
  • Critical input validation flaw in NetScaler ADC/Gateway SAML IDP enables memory overread and data access
  • Exploitation observed since March 27; ~30K NetScaler and 2K Gateway instances exposed, agencies must patch by April 2

The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new Citrix vulnerability to its catalog of known exploited flaws (KEV), signaling abuse in the wild, and urging government agencies to apply the fix immediately.

The bug in question is an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP. It can lead to memory overread which, in practical terms, can allow threat actors to access sensitive data, or run unauthorized actions.


https://cdn.mos.cms.futurecdn.net/TWkP7ZurZMY6uepDxsK6Ha-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img