Critical Known exploited (KEV) CVE-2026-3055

Out-of-Bounds Read in Citrix NetScaler (CVE-2026-3055) — Memory Leak in SAML IDP Configuration; Official NVD CVSS 9.8

Citrix NetScaler Added to KEV Mar 30, 2026 Federal remediation due 2026-04-02

Citrix NetScaler ADC/Gateway, an edge device, contains an out-of-bounds read flaw (CWE-125). When configured as a SAML IDP (the issuer of authentication), a memory overread occurs and internal memory contents can leak. CISA added it to the KEV on 2026-03-30, due 2026-04-02 (3 days). NVD's official (Primary) assessment is CVSS 9.8 (CRITICAL).

Key facts

  • CVE IDCVE-2026-3055
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Citrix NetScaler
  • CWECWE-125
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-02 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Out-of-bounds read (CWE-125) in Citrix NetScaler ADC/Gateway — a memory overread when configured as a SAML IDP can leak internal contents.
  • NVD's Primary assessment is CVSS 9.8 (CRITICAL); the assigning source's CVSS 4.0 assessment is 9.3.
  • A memory leak on an edge device can lead directly to session hijacking (the same pattern as CitrixBleed).
  • A leak while acting as a SAML IDP — the heart of authentication — means leaked material can be used to bypass authentication.
  • CISA added it to the KEV on 2026-03-30, due 2026-04-02 (3 days). The response is to update per Citrix's guidance.

An out-of-bounds read (CWE-125) is a defect in which a program reads beyond the memory region it allocated, into adjacent memory. The contents of memory that should never be accessible slip into a response and become visible to an external attacker — a path to information disclosure.

Per CISA, this occurs as a memory overread when NetScaler is configured as a SAML IDP (the role of asserting, via the SAML method, "this user is who they claim to be").

"Just a read" tends to sound minor, but a memory leak on an edge device is not to be dismissed. NetScaler ADC/Gateway sits precisely at the internet boundary — as the entry point for VPN, load balancing, and remote access from outside. Its memory can hold in-flight session information and fragments related to authentication.

The "CitrixBleed" family of incidents that caused major damage followed the same pattern: hijacking sessions via a memory leak from an edge device.

Here the leak occurs while the appliance acts as a SAML IDP — the very heart of authentication — so if leaked material is used to bypass authentication or hijack sessions, the impact goes well beyond "a little information is visible." NVD placing this at the top tier, CVSS 9.8 in its Primary assessment (high impact to confidentiality, integrity, and availability), reflects the weight of that outcome.

The response is to update per Citrix's guidance. Edge devices are exposed to the internet at all times and will be targeted continuously if left unaddressed. CISA's short 3-day remediation window underscores the urgency.

Why it matters

A memory leak on an edge device (the entry point for VPN and remote access) can escalate into session hijacking or authentication bypass via leaked session information and authentication fragments — not merely "a little information is visible." A leak while the appliance acts as a SAML IDP — the issuer of authentication — is especially destabilizing to an organization's access control. Rated 9.8 (CRITICAL) in NVD's Primary assessment, this makes prompt updating per Citrix's guidance, plus a review of edge-device configuration and exposure, a top priority.

FAQ

Is a "read-only" flaw really dangerous?
On an edge device, yes. Memory can hold session information and authentication fragments, so a leak can be used to bypass authentication or hijack sessions. The earlier CitrixBleed caused major damage through the same pattern.
Is it only an issue in SAML IDP configuration?
Per CISA, the flaw arises when NetScaler is configured as a SAML IDP (the issuer of authentication). Checking your configuration and updating per Citrix's guidance are the basics.
Why is the deadline as short as 3 days?
Edge devices are exposed to the internet at all times, so exploitation is especially pressing. CISA treats confirmed-exploited flaws with high priority and imposes short deadlines.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Citrix#NetScaler#CWE-125#Out-of-Bounds Read#SAML#Edge device#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.