<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Memory-Overread — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/memory-overread/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 31 Mar 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/memory-overread/feed.xml" rel="self" type="application/rss+xml"/><item><title>Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation</title><link>https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/</link><pubDate>Tue, 31 Mar 2026 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-citrix-netscaler-cve-2026-3055/</guid><description>Threat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.</description><content:encoded><![CDATA[<p>A critical vulnerability, CVE-2026-3055, impacts Citrix NetScaler ADC and NetScaler Gateway appliances configured as SAML identity providers (IDP). Disclosed on March 23, 2026, and actively exploited since at least March 27, 2026, this flaw allows attackers to perform memory overreads via the <code>/saml/login</code> and <code>/wsfed/passive</code> endpoints. Successful exploitation enables the extraction of sensitive information, including authenticated administrative session IDs. The vulnerability affects versions…</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>citrix</category><category>netscaler</category><category>cve-2026-3055</category><category>memory-overread</category><category>information-disclosure</category></item></channel></rss>