CVE-2026-3055

CRITICAL KEV NUCLEI

Insufficient input validation leading to memory overread

Title source: cna

Description

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Exploits (5)

nomisec SUSPICIOUS
by NetVanguard-cmd · poc
https://github.com/NetVanguard-cmd/CVE-2026-3055
nomisec SCANNER
by l0lsec · poc
https://github.com/l0lsec/check-cve-2026-3055-netscaler
nomisec SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-3055-Scanner---Herramienta-de-Detecci-n
nomisec SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC
nomisec WRITEUP
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-3055

Nuclei Templates (1)

Citrix NetScaler SAML IDP - Memory Overread
CRITICALVERIFIEDby watchtowr,shaikhyaser,DhiyaneshDk
Shodan: title:"NetScaler Gateway" || title:"NetScaler AAA" || http.favicon.hash:-1166125415 || http.favicon.hash:-1292923998
FOFA: title="NetScaler Gateway" || title="NetScaler AAA" || icon_hash="-1166125415" || icon_hash="-1292923998"

Scores

CVSS v3 9.8
EPSS 0.4519
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2026-03-30
VulnCheck KEV 2026-03-29
ENISA EUVD EUVD-2026-14546
CWE
CWE-125
Status published
Products (8)
citrix/netscaler_application_delivery_controller 13.1 - 13.1-37.262 (2 CPE variants)
citrix/netscaler_application_delivery_controller 13.1 - 13.1-62.23
citrix/netscaler_gateway 13.1 - 13.1-62.23
NetScaler/ADC 13.1 - 62.23
NetScaler/ADC 13.1 FIPS and NDcPP - 37.262
NetScaler/ADC 14.1 - 66.59
NetScaler/Gateway 13.1 - 62.23
NetScaler/Gateway 14.1 - 66.59
Published Mar 23, 2026
KEV Added Mar 30, 2026
Tracked Since Mar 24, 2026