Critical Known exploited (KEV) CVE-2026-3055

Out-of-Bounds Read in Citrix NetScaler (CVE-2026-3055) — Memory Leak in SAML IDP Configuration; Official NVD CVSS 9.8

Citrix NetScaler Added to KEV Mar 30, 2026 Federal remediation due 2026-04-02

Citrix NetScaler ADC/Gateway, an edge device, contains an out-of-bounds read flaw (CWE-125). When configured as a SAML IDP (the issuer of authentication), a memory overread occurs and internal memory contents can leak. CISA added it to the KEV on 2026-03-30, due 2026-04-02 (3 days). NVD's official (Primary) assessment is CVSS 9.8 (CRITICAL).

Key facts

  • CVE IDCVE-2026-3055
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)Citrix NetScaler
  • CWECWE-125
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-04-02 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Out-of-bounds read (CWE-125) in Citrix NetScaler ADC/Gateway — a memory overread when configured as a SAML IDP can leak internal contents.
  • NVD's Primary assessment is CVSS 9.8 (CRITICAL); the assigning source's CVSS 4.0 assessment is 9.3.
  • A memory leak on an edge device can lead directly to session hijacking (the same pattern as CitrixBleed).
  • A leak while acting as a SAML IDP — the heart of authentication — means leaked material can be used to bypass authentication.
  • CISA added it to the KEV on 2026-03-30, due 2026-04-02 (3 days). The response is to update per Citrix's guidance.
  • Edge device memory can hold session information in flight and fragments of authentication, so read-only still leads to intrusion.

1What an out-of-bounds read is

An out-of-bounds read (CWE-125) is a defect in which a program reads beyond the memory region it allocated, into adjacent memory. The contents of memory that should never be accessible slip into a response and become visible to an external attacker — a path to information disclosure.

Per CISA, this occurs as a memory overread when NetScaler is configured as a SAML IDP (the role of asserting, via the SAML method, "this user is who they claim to be").

2Why read-only is not minor here

"Just a read" tends to sound minor, but a memory leak on an edge device is not to be dismissed. NetScaler ADC/Gateway sits precisely at the internet boundary — as the entry point for VPN, load balancing, and remote access from outside. Its memory can hold in-flight session information and fragments related to authentication.

The "CitrixBleed" family of incidents that caused major damage followed the same pattern: hijacking sessions via a memory leak from an edge device.

Here the leak occurs while the appliance acts as a SAML IDP — the very heart of authentication — so if leaked material is used to bypass authentication or hijack sessions, the impact goes well beyond "a little information is visible." NVD placing this at the top tier, CVSS 9.8 in its Primary assessment (high impact to confidentiality, integrity, and availability), reflects the weight of that outcome.

3Devices permanently exposed to the internet

The response is to update per Citrix's guidance. Edge devices are exposed to the internet at all times and will be targeted continuously if left unaddressed. CISA's short 3-day remediation window underscores the urgency.

4Read-only still weighs heavily on an edge device

Read-only sounds light, yet a memory leak on an edge device cannot be treated lightly. What sits in that memory decides the outcome.

An ordinary information disclosureA memory leak on an edge device
What becomes visible is limitedSession information in flight and fragments of authentication can sit there
It does not lead directly to controlUsed to hijack a session it leads directly to intrusion
Impact stops at what was readWhere the device acts as a SAML IDP it reaches past authentication

NetScaler ADC and Gateway sit at the internet boundary as the entrance for VPN, load balancing and remote access from outside. The CitrixBleed incidents that did great damage previously followed the same shape: hijacking sessions through a memory leak from an edge device. NVD placing this at CVSS 9.8 in its primary assessment reflects the weight of that outcome.

Why it matters

A memory leak on an edge device (the entry point for VPN and remote access) can escalate into session hijacking or authentication bypass via leaked session information and authentication fragments — not merely "a little information is visible." A leak while the appliance acts as a SAML IDP — the issuer of authentication — is especially destabilizing to an organization's access control. Rated 9.8 (CRITICAL) in NVD's Primary assessment, this makes prompt updating per Citrix's guidance, plus a review of edge-device configuration and exposure, a top priority.

FAQ

Is a "read-only" flaw really dangerous?
On an edge device, yes. Memory can hold session information and authentication fragments, so a leak can be used to bypass authentication or hijack sessions. The earlier CitrixBleed caused major damage through the same pattern.
Is it only an issue in SAML IDP configuration?
Per CISA, the flaw arises when NetScaler is configured as a SAML IDP (the issuer of authentication). Checking your configuration and updating per Citrix's guidance are the basics.
Why is the deadline as short as 3 days?
Edge devices are exposed to the internet at all times, so exploitation is especially pressing. CISA treats confirmed-exploited flaws with high priority and imposes short deadlines.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Citrix#NetScaler#CWE-125#Out-of-Bounds Read#SAML#Edge device#KEV
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.