Summary
CVE-2026-3055 is a critical out-of-bounds memory read vulnerability (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway, rated CRITICAL with a CVSS 4.0 score of 9.3 and a CVSS 3.1 score of 9.8. The flaw resides in the SAML Identity Provider (SAML IDP) component and allows unauthenticated, remote attackers to trigger memory overread, potentially extracting active session tokens and sensitive credentials directly from appliance memory. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities (KEV) catalog on March 30, 2026, with a remediation due date of April 2, 2026, confirming active exploitation in the wild.
Technical details
- Root cause: Insufficient input validation in the SAML IDP processing logic of NetScaler ADC and NetScaler Gateway.
- Trigger condition: The appliance must be explicitly configured as a SAML Identity Provider (SAML IDP). Appliances in default configurations and Citrix-managed cloud instances are not affected.
- Attack vector: Unauthenticated, network-based HTTP/HTTPS requests — no privileges or user interaction required (AV:N / PR:N / UI:N).
- Impact: Successful exploitation causes an out-of-bounds read of appliance memory, enabling an attacker to leak sensitive in-memory data, including active session tokens and administrative credentials.
Affected software
- NetScaler ADC and NetScaler Gateway 14.1 — versions prior to 14.1-66.59
- NetScaler ADC and NetScaler Gateway 13.1 — versions prior to 13.1-62.23
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP — versions prior to 13.1-37.262
Severity
CVSS v3.1 base score: 9.8 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate — upgrade to the following patched versions:
- NetScaler ADC and NetScaler Gateway 14.1-66.59 or later
- NetScaler ADC and NetScaler Gateway 13.1-62.23 or later
- NetScaler ADC 13.1-FIPS / NDcPP 13.1-37.262 or later
- Interim workaround (if immediate patching is not possible): Citrix has released Global Deny List signatures for NetScaler builds 14.1-60.52 and 14.1-60.57 that can be applied without a device reboot to reduce exposure while a full upgrade is scheduled.
- Identify and audit all NetScaler appliances configured as SAML IDP. Apply network-level access controls to restrict unauthenticated access to SAML-related endpoints as an additional defensive layer.
IONIX Status
The IONIX threat lab ran a safe exploitability test on all relevant assets. The number of confirmed findings indicates how many assets can be exploited.

