Fortinet researchers confirmed large-scale exploitation of a critical memory overread vulnerability in Citrix NetScaler ADC and Gateway appliances, tracking the flaw as CVE-2026-3055 with a CVSS score of 9.3.
The vulnerability affects NetScaler systems configured as SAML Identity Providers, allowing unauthenticated remote attackers to leak potentially sensitive information from the appliance’s memory. Citrix disclosed the flaw and released patches, but exploitation has already been detected in the wild targeting organizations that delayed updates.
At least three organizations have been confirmed compromised through CVE-2026-3055, according to security researchers. The attacks exploit insufficient input validation that enables the memory overread, which in certain configurations can lead to remote code execution when the appliance processes specially crafted SAML requests.
Citrix noted that only systems configured as SAML Identity Providers are affected, and that Citrix-managed cloud services are not impacted. However, many enterprise deployments use the SAML IdP configuration for single sign-on integration, making this a high-priority patch for organizations relying on NetScaler for authentication.
The Canadian Centre for Cyber Security issued advisory AL26-006, urging organizations to apply theCitrix patches immediately or disable the SAML IdP configuration if patching is not feasible. The advisory emphasized that the vulnerability requires no authentication to exploit, making internet-facing instances particularly vulnerable.
The flaw was initially classified as a memory leak but was later upgraded to a more severe assessment after researchers demonstrated that the overread could be chained with other techniques to achieve code execution. This reclassification raised the urgency for organizations that may have initially deprioritized the update.
The exploitation of CVE-2026-3055 follows a pattern of critical vulnerabilities in enterprise network equipment being weaponized within days of disclosure. Security teams are advised to audit NetScaler configurations, verify SAML IdP settings, and ensure all appliances are running the latest patched firmware.
With active exploitation confirmed and the vulnerability carrying a near-maximum severity score, organizations running Citrix NetScaler should treat this as an emergency patching priority to prevent potential data exposure or system compromise.
Sources: Horizon3.ai Analysis, Canadian Cyber Centre Advisory, Hadrian Security Research
Author: Technology Desk
discussion