CVE-2026-3055
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
- Affected products
- Netscaler Adc, Netscaler Gateway
- Citrix Netscaler Application Delivery Controller
- < 13.1-37.262, 13.1-62.23, 14.1-60.58
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 84.5% (100th percentile)
- Weakness
- CWE-125
- NVD status
- Analyzed
- Published
- 2026-03-23
CVE-2026-3055 at NVD
6 known exploits for CVE-2026-3055
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for Out-of-bounds Read in Citrix Netscaler_Application_Delivery_Controller
Exploit for CVE-2026-3055
Citrix ADC (NetScaler) CVE-2026-3055 Scanner