CVE-2026-3055
CRITICAL KEV NUCLEIInsufficient input validation leading to memory overread
Title source: cnaExploitation Summary
CVE-2026-3055 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 30, 2026.
EIP tracks 7 public exploits from researchers including SecureWithUmer, NetVanguard-cmd, l0lsec, including a Metasploit module auxiliary/scanner/http/citrix_netscaler_cve_2026_3055.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a Python-based scanner for detecting CVE-2026-3055, a memory leak vulnerability in Citrix NetScaler. The scanner checks for the presence of the NSC_TASS cookie and analyzes its contents for sensitive data leaks, including session IDs and HTTP headers, but does not exploit the vulnerability.
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Exploits (7)
This repository contains a Python-based scanner for detecting CVE-2026-3055, a memory leak vulnerability in Citrix NetScaler. The scanner checks for the presence of the NSC_TASS cookie and analyzes its contents for sensitive data leaks, including session IDs and HTTP headers, but does not exploit the vulnerability.
The repository claims to exploit CVE-2026-3055, a memory overread vulnerability in NetScaler ADC/Gateway SAML IDP, but provides no actual exploit code. Instead, it directs users to an external download link (tinyurl.com), which is a common tactic for distributing malware or fake exploits.
This repository contains a Python script that scans for CVE-2026-3055, a memory overread vulnerability in Citrix NetScaler appliances configured as SAML Identity Providers. The script sends a crafted SAML request to detect the presence of the vulnerability by checking for specific response markers.
This repository contains a Python-based scanner for detecting CVE-2026-3055, a memory overread vulnerability in Citrix NetScaler ADC and Gateway. The tool checks for memory leaks via the NSC_TASS cookie and extracts session IDs from leaked data.
The repository contains a Python script that checks for the presence of CVE-2026-3055 in Citrix NetScaler by sending a request to the vulnerable endpoint and analyzing the response cookies for signs of memory leakage. It does not include exploit code but provides a detection mechanism.
This repository provides a detailed technical analysis of CVE-2026-3055, an unauthenticated out-of-bounds memory read vulnerability in Citrix NetScaler ADC and Gateway when configured as a SAML Identity Provider (IdP). It includes vulnerability details, affected versions, remediation steps, and references but does not contain exploit code.
This Metasploit module scans for CVE-2026-3055, a memory leak vulnerability in Citrix ADC (NetScaler) SAML IdP configurations. It detects the presence of the vulnerability by checking for leaked memory in the NSC_TASS cookie and attempts to extract session cookies from the leaked data.
Nuclei Templates (1)
title:"NetScaler Gateway" || title:"NetScaler AAA" || http.favicon.hash:-1166125415 || http.favicon.hash:-1292923998
title="NetScaler Gateway" || title="NetScaler AAA" || icon_hash="-1166125415" || icon_hash="-1292923998"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H