{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/marimo--0.23.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*","cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*","cpe:2.3:a:n8n:n8n:1.121.0:*:*:*:*:node.js:*:*","cpe:2.3:a:coreweave:marimo:*:*:*:*:*:python:*:*"],"_cs_cves":[{"id":"CVE-2026-4368"},{"cvss":9.8,"id":"CVE-2026-33017"},{"cvss":10,"id":"CVE-2026-21858"},{"cvss":9.9,"id":"CVE-2025-68613"},{"cvss":9.8,"id":"CVE-2026-39987"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["Langflow (\u003c 1.9.0)","n8n (\u003c 1.121.1)","Marimo (\u003c 0.23.0)","NetScaler ADC","NetScaler Gateway"],"_cs_severities":["critical"],"_cs_tags":["citrix","netscaler","cve-2026-3055","memory-overread","information-disclosure"],"_cs_type":"threat","_cs_vendors":["Langflow","n8n","Marimo","Citrix"],"content_html":"\u003cp\u003eA critical vulnerability, CVE-2026-3055, impacts Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML identity providers (IDP). Disclosed on March 23, 2026, and actively exploited since at least March 27, 2026, this flaw allows attackers to perform memory overreads via the \u003ccode\u003e/saml/login\u003c/code\u003e and \u003ccode\u003e/wsfed/passive\u003c/code\u003e endpoints. Successful exploitation enables the extraction of sensitive information, including authenticated administrative session IDs. The vulnerability affects versions before 14.1-60.58, older than 13.1-62.23, and older than 13.1-37.262. The observed exploitation, detected by watchTowr, involves threat actors using known source IPs to target vulnerable instances. The incomplete disclosure of the security issue in Citrix's bulletin has raised concerns. ShadowServer Foundation reported approximately 29,000 exposed NetScaler and 2,250 Gateway instances as of March 28, 2026.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a vulnerable Citrix NetScaler ADC or Gateway appliance configured as a SAML IdP.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted request to the \u003ccode\u003e/saml/login\u003c/code\u003e or \u003ccode\u003e/wsfed/passive\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eDue to the memory overread vulnerability (CVE-2026-3055), the appliance leaks sensitive information from its memory.\u003c/li\u003e\n\u003cli\u003eThe leaked information includes authenticated administrative session IDs.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the leaked administrative session IDs.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the captured session IDs to authenticate to the NetScaler appliance with administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker gains full control over the NetScaler appliance.\u003c/li\u003e\n\u003cli\u003eThe attacker can then perform further actions such as data exfiltration, configuration changes, or deploying malicious payloads.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-3055 can lead to full takeover of vulnerable Citrix NetScaler ADC and Gateway appliances. This allows attackers to steal sensitive data, modify configurations, and potentially pivot to internal networks. With approximately 29,000 exposed NetScaler and 2,250 Gateway instances online, a significant number of organizations are potentially at risk. The compromise of these appliances can disrupt critical services, lead to data breaches, and damage organizational reputation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately patch all Citrix NetScaler ADC and Gateway appliances to versions 14.1-60.58, 13.1-62.23, or 13.1-37.262 or later to remediate CVE-2026-3055 and CVE-2026-4368.\u003c/li\u003e\n\u003cli\u003eApply mitigations if patching is not immediately feasible, focusing on appliances configured as SAML identity providers (IDP).\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to your SIEM to detect exploitation attempts against the \u003ccode\u003e/saml/login\u003c/code\u003e and \u003ccode\u003e/wsfed/passive\u003c/code\u003e endpoints.\u003c/li\u003e\n\u003cli\u003eReview logs for unusual activity on NetScaler appliances, particularly requests to the \u003ccode\u003e/saml/login\u003c/code\u003e and \u003ccode\u003e/wsfed/passive\u003c/code\u003e endpoints, to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T12:35:51Z","date_published":"2026-03-31T12:00:00Z","id":"https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/","summary":"Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.","title":"Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation","url":"https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/"}],"language":"en","title":"CraftedSignal Threat Feed - Marimo (\u003c 0.23.0)","version":"https://jsonfeed.org/version/1.1"}