2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
Cybersecurity Classified by Officially
Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway [1]. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations.
At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation.
The advisory describes two vulnerabilities:
The vulnerability CVE-2026-3055, with a CVSS score of 9.3, is an out-of-bounds read vulnerability that may result in memory overread. Successful exploitation could allow an attacker to access sensitive information from memory. This issue affects systems configured as a SAML Identity Provider (IdP) [1].
The vulnerability CVE-2026-4368, with a CVSS score of 7.7, is a race condition that may lead to user session mix-up. Exploitation could allow one user to gain access to another user’s session. This issue affects systems configured as a Gateway (e.g. SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server [1].
The vulnerabilities affect NetScaler ADC and NetScaler Gateway versions:
Citrix also identified a known issue in builds 14.1-66.54 and 14.1-66.59 affecting STA server binding configuration. When the STA server is configured using the full path (/scripts/ctxsta.dll), binding may fail, impacting authentication flows [2].
Additional information is available in the vendor’s advisory [1].
CERT-EU strongly recommends taking the following actions:
This is an extract. The publication continues at the source.
Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-003/
Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT-EU — imported from official source
- Official source
- https://www.cert.europa.eu/publications/security-advisories-rss RSS
- Imported
- September 15, 2026 20:57
- Versions
- 1 recorded
- Identity
security-advisories-10940