CVE-2026-3055CISA KEV: Actively Exploited

Citrix NetScaler Out-of-Bounds Read Vulnerability

Published Mar 30, 2026·Updated Mar 30, 2026

Description

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

Public Exploits & PoCs4 found

PoC: check-cve-2026-3055-netscaler

Low-impact probe for Citrix NetScaler CVE-2026-3055 (SAML IdP memory overread)

PoC: CVE-2026-3055-Scanner---Herramienta-de-Detecci-n

Herramienta de detección para CVE-2026-3055 que identifica NetScaler ADC y Gateway vulnerables a memory overread. Realiza escaneo individual, por red o lista de hosts, detecta memory leak en /wsfed/passive?wctx, extrae session IDs, verifica versiones y genera reportes JSON, HTML o CSV con hosts vulnerables.

PoC: CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC

Exploit funcional para CVE-2026-3055 en Citrix NetScaler ADC y Gateway. Aprovecha memory overread en endpoint /wsfed/passive?wctx para filtrar memoria del sistema, extrayendo session IDs administrativas, cookies y datos sensibles que permiten hijacking de sesiones y compromiso total del appliance vulnerable.

PoC: CVE-2026-3055

CVE-2026-3055

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free