Out-of-bounds read in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-3055
Published: March 23, 2026 / Updated: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a boundary condition in SAML IDP. A remote attacker can send a specially crafted request the appliance, trigger an out-of-bounds read error and read contents of memory on the system.
Successful exploitation of the vulnerability may lead to full system compromise.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-3055
Citrix NetScaler Gateway - addressed in versions 13.1-62.23, 14.1-66.59
Links to Public Exploits and PoC-codes
- Exploit #12716 - Citrix ADC (NetScaler) CVE-2026-3055 Scanner (May 20, 2026)
- Exploit #12525 - CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC (Exploit funcional para CVE-2026-3055 en Citrix NetScaler ADC y Gateway. Aprovecha memory overread en endpoint /wsfed/passive?wctx para filtrar memoria del sistema, extrayendo session IDs administrativa (April 1, 2026)