This page may contain stale information. Last updated: 2026-06-03

Definition

Security considerations for SAML Identity Provider configurations on perimeter appliances like VPN/ADC gateways.

Key Points

  • CVE-2026-3055: memory overread on NetScaler SAML IdP (CVSS 9.3)
  • Active exploitation pattern similar to CitrixBleed (CVE-2023-4966)
  • Affected endpoints include /saml/login and /wsfed/passive
  • CISA KEV catalog entry; patch immediately

Sources