CVE-2026-3055
Insufficient input validation leading to memory overread
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
In plain language
AI Act nowCVE-2026-3055 is a serious flaw in Citrix ADC / NetScaler Gateway when they’re set up as a SAML IDP: an attacker can trigger a memory “read past the end” to expose data or crash the system, without needing a login. If you run this SAML IDP setup, you should act immediately.
In Citrix ADC / NetScaler Gateway, when configured as a SAML IDP, insufficient input validation can lead to a network-triggered memory overread (CWE-125), allowing potential sensitive data exposure and/or denial of service without authentication.
What to do now
- Check whether your Citrix ADC / NetScaler Gateway is configured as a SAML IDP (Service Provider / Identity Provider role) and whether your gateway is internet-reachable.
- If it is a SAML IDP, upgrade to the fixed versions: ADC fixed in 66.59 or 62.23 or 37.262; Gateway fixed in 66.59 or 62.23; netscaler application delivery controller fixed in 13.1-37.262; netscaler gateway fixed in 13.1-62.23.
- If you cannot upgrade right away, follow Citrix vendor mitigations from their guidance for CVE-2026-3055 and implement them immediately.
- Confirm after changes that the SAML IDP functions still work and monitor availability and error logs for unusual spikes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploiteden·The Hacker News· Exploited Langflow knaithe
- Китайский хакер использовал DeepSeek для проведения автономных атакru-ru·Хакер (xakep.ru)· Exploited Langflow knaithe
- Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable serversen-us·Help Net Security· Research DeepSeek Knaithe
- Hacker uses DeepSeek AI to autonomously attack vulnerable serversen-us·BleepingComputer· Exploited Langflow knaithe
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksen·The Hacker News· Exploited Langflow knaithe
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Storiesen·The Hacker News· Roundup xplogs22 phishing
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacksen-us·Palo Alto Unit 42· PoC Hermes Agent knaithe
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Serviceen·The Hacker News· Patch NetScaler ADC network-edge
- CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)en·watchTowr Labs· Research NetScaler ADC network-edge
- Metasploit Wrap Up 05/29/2026en·Rapid7 Blog· Roundup Metasploit Framework rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-3055 and every CVE in our database. Create a free account — no credit card required.
Create Free Account