By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks
Computing

Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks

News Room
Last updated: 2026/03/24 at 3:33 AM
News Room Published 24 March 2026
Share
Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks
SHARE

Ravie LakshmananMar 24, 2026Vulnerability / Enterprise Security

Citrix has released security updates to address two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application.

The vulnerabilities are listed below –

  • CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory overread
  • CVE-2026-4368 (CVSS score: 7.7) – Race condition leading to user session mixup

Cybersecurity company Rapid7 said that CVE-2026-3055 refers to an out-of-bounds read that could be exploited by unauthenticated remote attackers to leak potentially sensitive information from the appliance’s memory.

However, for exploitation to be successful, the Citrix ADC or Citrix Gateway appliance must be configured as a SAML Identity Provider (SAML IDP), which means default configurations are unaffected. To determine if the device has been configured as a SAML IDP Profile, Citrix is urging customers to inspect their NetScaler Configuration for the specified string: “add authentication samlIdPProfile .*”

CVE-2026-4368, on the other hand, requires the appliance to be configured as a gateway (i.e., SSL VPN, ICA Proxy, CVPN, and RDP Proxy) or an Authentication, Authorization, and Accounting (AAA) server. Customers can check the NetScaler Configuration to ascertain if their devices have been configured as either of the nodes –

  • AAA virtual server – add authentication vserver .*
  • Gateway – add vpn vserver .*

The vulnerabilities affect NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59 and 13.1 before 13.1-62.23, as well as NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. Users are advised to apply the latest updates as soon as possible for optimal protection.

While there is no evidence that the shortcomings have been exploited in the wild, security flaws in NetScaler devices have been repeatedly exploited by threat actors (CVE-2023-4966, aka Citrix Bleed, CVE-2025-5777, aka Citrix Bleed 2, CVE-2025-6543, and CVE-2025-7775), making it imperative that users take steps to update their instances.

“CVE-2026-3055 allows unauthenticated attackers to leak and read sensitive memory from NetScaler ADC deployments. If it sounds familiar, it’s because it is – this vulnerability sounds suspiciously similar to Citrix Bleed and Citrix Bleed 2, which continue to represent a trauma event for many,” watchTowr CEO and founder Benjamin Harris told The Hacker News.

“NetScalers are critical solutions that have been continuously targeted for initial access into enterprise environments. While the advisory just went live, defenders need to act quickly. Anyone running impacted versions needs to patch urgently. Imminent exploitation is highly likely.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Lock Down Your Taxes: LifeLock’s Fraud Prevention Guide Lock Down Your Taxes: LifeLock’s Fraud Prevention Guide
Next Article Why MeDo is the Best No-Code App Builder of 2026 Why MeDo is the Best No-Code App Builder of 2026
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Apple WWDC 2026: Everything we know so far
Apple WWDC 2026: Everything we know so far
Software
Today's NYT Strands Hints, Answer and Help for March 24 #751 – CNET
Today's NYT Strands Hints, Answer and Help for March 24 #751 – CNET
News
The US bans consumer and small business routers manufactured in third countries
The US bans consumer and small business routers manufactured in third countries
Mobile
Why Instagram Notes Are the Most Underrated Growth Tool in 2026
Why Instagram Notes Are the Most Underrated Growth Tool in 2026
Computing

You Might also Like

Why Instagram Notes Are the Most Underrated Growth Tool in 2026
Computing

Why Instagram Notes Are the Most Underrated Growth Tool in 2026

15 Min Read
NVIDIA Talks Up “Expanding The Open-Source Horizon” Around AI & Kubernetes
Computing

NVIDIA Talks Up “Expanding The Open-Source Horizon” Around AI & Kubernetes

2 Min Read
YMTC advances homegrown chipmaking technology · TechNode
Computing

YMTC advances homegrown chipmaking technology · TechNode

1 Min Read
KOKO Networks’ UK unit grew revenue more than 20x in 2024. It still collapsed
Computing

KOKO Networks’ UK unit grew revenue more than 20x in 2024. It still collapsed

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?