Skip to content
Threat Feed
critical threat PoC updated

Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation

Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.

What's new

  • 1. poc_available; added CVE-2025-68613 +4 Jul 31, 12:35 via the-hacker-news

A critical vulnerability, CVE-2026-3055, impacts Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML identity providers (IDP). Disclosed on March 23, 2026, and actively exploited since at least March 27, 2026, this flaw allows attackers to perform memory overreads via the /saml/login and /wsfed/passive endpoints. Successful exploitation enables the extraction of sensitive information, including authenticated administrative session IDs. The vulnerability affects versions before 14.1-60.58, older than 13.1-62.23, and older than 13.1-37.262. The observed exploitation, detected by watchTowr, involves threat actors using known source IPs to target vulnerable instances. The incomplete disclosure of the security issue in Citrix's bulletin has raised concerns. ShadowServer Foundation reported approximately 29,000 exposed NetScaler and 2,250 Gateway instances as of March 28, 2026.

Attack Chain

  1. The attacker identifies a vulnerable Citrix NetScaler ADC or Gateway appliance configured as a SAML IdP.
  2. The attacker sends a crafted request to the /saml/login or /wsfed/passive endpoint.
  3. Due to the memory overread vulnerability (CVE-2026-3055), the appliance leaks sensitive information from its memory.
  4. The leaked information includes authenticated administrative session IDs.
  5. The attacker captures the leaked administrative session IDs.
  6. The attacker uses the captured session IDs to authenticate to the NetScaler appliance with administrative privileges.
  7. The attacker gains full control over the NetScaler appliance.
  8. The attacker can then perform further actions such as data exfiltration, configuration changes, or deploying malicious payloads.

Impact

Successful exploitation of CVE-2026-3055 can lead to full takeover of vulnerable Citrix NetScaler ADC and Gateway appliances. This allows attackers to steal sensitive data, modify configurations, and potentially pivot to internal networks. With approximately 29,000 exposed NetScaler and 2,250 Gateway instances online, a significant number of organizations are potentially at risk. The compromise of these appliances can disrupt critical services, lead to data breaches, and damage organizational reputation.

Recommendation

  • Immediately patch all Citrix NetScaler ADC and Gateway appliances to versions 14.1-60.58, 13.1-62.23, or 13.1-37.262 or later to remediate CVE-2026-3055 and CVE-2026-4368.
  • Apply mitigations if patching is not immediately feasible, focusing on appliances configured as SAML identity providers (IDP).
  • Deploy the Sigma rules provided in this brief to your SIEM to detect exploitation attempts against the /saml/login and /wsfed/passive endpoints.
  • Review logs for unusual activity on NetScaler appliances, particularly requests to the /saml/login and /wsfed/passive endpoints, to identify potential exploitation attempts.

Detection coverage 2

Detect Access to Citrix NetScaler SAML Login Endpoint

high

Detects access to the /saml/login endpoint of Citrix NetScaler, which is targeted by CVE-2026-3055 exploitation attempts.

sigma tactics: initial_access techniques: T1190 sources: webserver, linux

Detect Access to Citrix NetScaler WSFED Passive Endpoint

high

Detects access to the /wsfed/passive endpoint of Citrix NetScaler, which is targeted by CVE-2026-3055 exploitation attempts.

sigma tactics: initial_access techniques: T1190 sources: webserver, linux

Detection queries are available on the platform. Get full rules →

Indicators of compromise

1

domain

TypeValue
domaingithub.com