CRITICAL
CVE-2026-3055
CVSS
9.8
KEV
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Summary dbcve.org
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML Identity Provider (IDP) allows an attacker to read sensitive memory contents beyond intended boundaries. The memory overread could expose session tokens, credentials, or other sensitive data in heap memory.
Mitigation
Apply the Citrix security patch when released. Minimize attack surface by restricting access to SAML IDP endpoints to trusted networks only until the patch can be applied.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
87.17%
Probability of exploitation in next 30 days
99.7th percentile
References
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
Vendor Advisory
https://labs.watchtowr.com/please-we-beg-just-one-weekend-free-of-appliances-citrix-netscaler-cve-2026-3055-memory-overread-part-2/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3055
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.