2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

Imported from official source

Advisory

Cybersecurity Classified by Officially

Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

  • 23/03/2026 --- v1.0 -- Initial publication
  • On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway [1]. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations.

    At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.

    The advisory describes two vulnerabilities:

    The vulnerability CVE-2026-3055, with a CVSS score of 9.3, is an out-of-bounds read vulnerability that may result in memory overread. Successful exploitation could allow an attacker to access sensitive information from memory. This issue affects systems configured as a SAML Identity Provider (IdP) [1].

    The vulnerability CVE-2026-4368, with a CVSS score of 7.7, is a race condition that may lead to user session mix-up. Exploitation could allow one user to gain access to another user’s session. This issue affects systems configured as a Gateway (e.g. SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server [1].

    The vulnerabilities affect NetScaler ADC and NetScaler Gateway versions:

  • prior to 13.1-37.262 (FIPS and NDcPP) - only for NetScaler ADC
  • Citrix also identified a known issue in builds 14.1-66.54 and 14.1-66.59 affecting STA server binding configuration. When the STA server is configured using the full path (/scripts/ctxsta.dll), binding may fail, impacting authentication flows [2].

    Additional information is available in the vendor’s advisory [1].

    CERT-EU strongly recommends taking the following actions:

  • restrict access to NetScaler Gateway and AAA virtual servers using network-level controls (e.g. IP allowlisting) until updates are deployed;
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-003/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    1 recorded
    Identity
    security-advisories-10940

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.