CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Vulnerability
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Other sources
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway), and NetScaler ADC FIPS and NDcPP if mitigations are unavailable.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3055?
CVE-2026-3055 has been classified as a critical severity vulnerability due to its potential to lead to memory overread.
How do I fix CVE-2026-3055?
To fix CVE-2026-3055, you should update to the latest version of Citrix NetScaler ADC or NetScaler Gateway that addresses this vulnerability.
What products are affected by CVE-2026-3055?
CVE-2026-3055 affects Citrix NetScaler ADC and Citrix NetScaler Gateway when configured as a SAML IDP.
What type of vulnerability is CVE-2026-3055?
CVE-2026-3055 is an insufficient input validation vulnerability that can lead to memory overread.
Can CVE-2026-3055 be exploited remotely?
Yes, CVE-2026-3055 can potentially be exploited remotely, increasing the risk of unauthorized access.