CWE-CWE-125

Citrix NetScaler Memory Overread (CVE-2026-3055)

Severity:
Critical
Summary
Citrix NetScaler ADC and NetScaler Gateway contain an insufficient input validation vulnerability when configured as a SAML Identity Provider (IDP). The flaw allows unauthenticated attackers to trigger a memory overread by sending a crafted SAML authentication request to the /saml/login endpoint. Successful exploitation can expose sensitive in-memory data or destabilize the appliance.
Impact
An unauthenticated attacker can read arbitrary memory from the NetScaler process, potentially exposing session tokens, credentials, or other sensitive data, and may cause application instability or denial of service.
Remediation
Update Citrix NetScaler ADC and NetScaler Gateway to the latest patched version. As a workaround, restrict access to the vulnerable endpoint WAF rules. Review application logs for indicators of exploitation.
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding