A critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-3055, allows unauthenticated remote code execution when the appliance is configured as a SAML Identity Provider. The vulnerability carries a CVSS score of 9.8 and large-scale active exploitation has been confirmed by Fortinet’s threat intelligence team. Organisations running NetScaler appliances with SAML IDP functionality enabled are at immediate risk.

What Is the Vulnerability?

CVE-2026-3055 is an out-of-bounds read vulnerability caused by insufficient input validation in NetScaler ADC and NetScaler Gateway when operating as a SAML Identity Provider (IDP). A remote attacker can send specially crafted SAML-related requests to the appliance, triggering a memory overread condition that can be exploited for arbitrary code execution.

Citrix NetScaler appliances serve as the primary remote access and application delivery gateway for thousands of organisations worldwide — they sit at the network perimeter handling VPN termination, load balancing, and SAML-based single sign-on authentication. The SAML IDP functionality is the component that issues SAML assertions to authenticate users to downstream applications. A compromise at this layer allows an attacker to forge SAML assertions, impersonate any user, intercept authentication traffic, and establish persistent access to internal applications.

The vulnerability is classified under CWE-125 (Out-of-Bounds Read):

  • CVSS v3.1 Score: 9.8 (Critical)
  • Attack Vector: Network (AV:N)
  • Attack Complexity: Low (AC:L)
  • Privileges Required: None (PR:N)
  • User Interaction: None (UI:N)
  • Impact: High on confidentiality, integrity, and availability (C:H/I:H/A:H)

Which Versions Are Affected?

The vulnerability affects all Citrix NetScaler ADC and NetScaler Gateway versions prior to the fixed releases:

  • NetScaler ADC (standard builds): all versions prior to 13.1-62.23
  • NetScaler ADC (standard builds, 14.x branch): all versions prior to 14.1-60.58
  • NetScaler ADC (FIPS builds): all versions prior to 13.1-37.262
  • NetScaler ADC (NDcPP builds): all versions prior to 13.1-37.262
  • NetScaler Gateway (standard): all versions prior to 13.1-62.23
  • NetScaler Gateway (14.x branch): all versions prior to 14.1-60.58

The vulnerability is exploitable only when NetScaler is configured as a SAML Identity Provider.

Is It Being Exploited in the Wild?

Yes — confirmed large-scale active exploitation. Fortinet’s threat intelligence team has reported large-scale exploitation of CVE-2026-3055 against internet-facing NetScaler appliances configured as SAML IDPs. This follows the well-established pattern of NetScaler vulnerabilities being among the most aggressively exploited in the wild. Historical precedent is unambiguous: CVE-2023-4966 (CitrixBleed) and CVE-2023-3519 were both weaponised within days of disclosure and used in widespread ransomware and data theft campaigns against thousands of organisations globally.

What Is the Fix?

Citrix has released patched versions addressing CVE-2026-3055. Update to the following minimum versions:

  • NetScaler ADC 13.1 branch: Upgrade to 13.1-62.23 or later (standard) or 13.1-37.262 or later (FIPS/NDcPP)
  • NetScaler ADC 14.1 branch: Upgrade to 14.1-60.58 or later
  • NetScaler Gateway 13.1 branch: Upgrade to 13.1-62.23 or later
  • NetScaler Gateway 14.1 branch: Upgrade to 14.1-60.58 or later

Recommendations

Patch immediately. Large-scale exploitation is confirmed and ongoing. Verify SAML IDP configuration. Hunt for signs of compromise including unusual SAML assertion activity, IDP-initiated logins, connections from unrecognised IP addresses, and unexpected changes to SAML configuration or signing certificates. Audit your NetScaler inventory across all data centres and DR sites. Rotate SAML signing certificates after patching if exploitation is suspected.

References

  • Citrix Security Bulletin — CTX696300
  • NVD: CVE-2026-3055
  • Vulnerability Intelligence Report — June 2, 2026