CVE-2026-3055
CRITICAL KEV NUCLEIInsufficient input validation leading to memory overread
Title source: cnaDescription
Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
Exploits (5)
nomisec
SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-3055-Scanner---Herramienta-de-Detecci-n
nomisec
SCANNER
by fevar54 · poc
https://github.com/fevar54/CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC
Nuclei Templates (1)
Citrix NetScaler SAML IDP - Memory Overread
CRITICALVERIFIEDby watchtowr,shaikhyaser,DhiyaneshDk
Shodan:
title:"NetScaler Gateway" || title:"NetScaler AAA" || http.favicon.hash:-1166125415 || http.favicon.hash:-1292923998
FOFA:
title="NetScaler Gateway" || title="NetScaler AAA" || icon_hash="-1166125415" || icon_hash="-1292923998"
References (3)
Scores
CVSS v3
9.8
EPSS
0.4519
EPSS Percentile
97.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-03-30
VulnCheck KEV
2026-03-29
ENISA EUVD
EUVD-2026-14546
CWE
CWE-125
Status
published
Products (8)
citrix/netscaler_application_delivery_controller
13.1 - 13.1-37.262 (2 CPE variants)
citrix/netscaler_application_delivery_controller
13.1 - 13.1-62.23
citrix/netscaler_gateway
13.1 - 13.1-62.23
NetScaler/ADC
13.1 - 62.23
NetScaler/ADC
13.1 FIPS and NDcPP - 37.262
NetScaler/ADC
14.1 - 66.59
NetScaler/Gateway
13.1 - 62.23
NetScaler/Gateway
14.1 - 66.59
Published
Mar 23, 2026
KEV Added
Mar 30, 2026
Tracked Since
Mar 24, 2026