<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Langflow (&lt; 1.9.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/langflow--1.9.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 31 Mar 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/langflow--1.9.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation</title><link>https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/</link><pubDate>Tue, 31 Mar 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/</guid><description>Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.</description><content:encoded><![CDATA[<p>A critical vulnerability, CVE-2026-3055, impacts Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML identity providers (IDP). Disclosed on March 23, 2026, and actively exploited since at least March 27, 2026, this flaw allows attackers to perform memory overreads via the <code>/saml/login</code> and <code>/wsfed/passive</code> endpoints. Successful exploitation enables the extraction of sensitive information, including authenticated administrative session IDs. The vulnerability affects versions before 14.1-60.58, older than 13.1-62.23, and older than 13.1-37.262. The observed exploitation, detected by watchTowr, involves threat actors using known source IPs to target vulnerable instances. The incomplete disclosure of the security issue in Citrix's bulletin has raised concerns. ShadowServer Foundation reported approximately 29,000 exposed NetScaler and 2,250 Gateway instances as of March 28, 2026.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies a vulnerable Citrix NetScaler ADC or Gateway appliance configured as a SAML IdP.</li>
<li>The attacker sends a crafted request to the <code>/saml/login</code> or <code>/wsfed/passive</code> endpoint.</li>
<li>Due to the memory overread vulnerability (CVE-2026-3055), the appliance leaks sensitive information from its memory.</li>
<li>The leaked information includes authenticated administrative session IDs.</li>
<li>The attacker captures the leaked administrative session IDs.</li>
<li>The attacker uses the captured session IDs to authenticate to the NetScaler appliance with administrative privileges.</li>
<li>The attacker gains full control over the NetScaler appliance.</li>
<li>The attacker can then perform further actions such as data exfiltration, configuration changes, or deploying malicious payloads.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-3055 can lead to full takeover of vulnerable Citrix NetScaler ADC and Gateway appliances. This allows attackers to steal sensitive data, modify configurations, and potentially pivot to internal networks. With approximately 29,000 exposed NetScaler and 2,250 Gateway instances online, a significant number of organizations are potentially at risk. The compromise of these appliances can disrupt critical services, lead to data breaches, and damage organizational reputation.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately patch all Citrix NetScaler ADC and Gateway appliances to versions 14.1-60.58, 13.1-62.23, or 13.1-37.262 or later to remediate CVE-2026-3055 and CVE-2026-4368.</li>
<li>Apply mitigations if patching is not immediately feasible, focusing on appliances configured as SAML identity providers (IDP).</li>
<li>Deploy the Sigma rules provided in this brief to your SIEM to detect exploitation attempts against the <code>/saml/login</code> and <code>/wsfed/passive</code> endpoints.</li>
<li>Review logs for unusual activity on NetScaler appliances, particularly requests to the <code>/saml/login</code> and <code>/wsfed/passive</code> endpoints, to identify potential exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>citrix</category><category>netscaler</category><category>cve-2026-3055</category><category>memory-overread</category><category>information-disclosure</category></item></channel></rss>