{"id":11655,"date":"2026-03-27T10:03:50","date_gmt":"2026-03-27T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/27\/critical-citrix-netscaler-and-gateway-vulnerabilities-let-remote-attackers-leak-sensitive-information\/"},"modified":"2026-03-27T10:03:50","modified_gmt":"2026-03-27T10:03:50","slug":"critical-citrix-netscaler-and-gateway-vulnerabilities-let-remote-attackers-leak-sensitive-information","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/27\/critical-citrix-netscaler-and-gateway-vulnerabilities-let-remote-attackers-leak-sensitive-information\/","title":{"rendered":"Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information"},"content":{"rendered":"<p>    Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cloud Software Group has issued a critical security bulletin detailing two newly discovered vulnerabilities affecting customer-managed <a href=\"https:\/\/cybersecuritynews.com\/netscaler-adc-and-gateway-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">NetScaler ADC and NetScaler Gateway appliances.<\/a><\/p>\n<p>These flaws, tracked as CVE-2026-3055 and CVE-2026-4368, could allow remote attackers to <a href=\"https:\/\/cybersecuritynews.com\/audi-volkswagen-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">leak sensitive information<\/a> or cause user session mixups.<\/p>\n<p>Network administrators and security teams are strongly urged to <a href=\"https:\/\/cybersecuritynews.com\/android-security-patches\/\" target=\"_blank\" rel=\"noreferrer noopener\">apply the latest security patches<\/a> immediately to prevent potential network compromise.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-citrix-netscaler-and-gateway-vulnerabilities\"><strong>Citrix NetScaler and Gateway Vulnerabilities<\/strong><\/h2>\n<p>The security bulletin outlines two distinct vulnerabilities affecting different configurations of the NetScaler appliances.<\/p>\n<p>The most severe of the two flaws is <a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-3055, an out-of-bounds read vulnerability<\/a> caused by insufficient input validation. Earning a critical base score of 9.3, this flaw enables remote attackers to trigger a memory overread.<\/p>\n<p>An out-of-bounds read allows an attacker to access memory locations beyond a buffer\u2019s intended boundaries, potentially <a href=\"https:\/\/cybersecuritynews.com\/vvs-stealer-attacking-discord-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">exposing sensitive operational data, credentials, or session tokens.<\/a><\/p>\n<p>However, exploitation is conditionally restricted. The vulnerability only affects appliances explicitly <a href=\"https:\/\/cybersecuritynews.com\/golden-saml-attack-let-attackers-gains-control\/\" target=\"_blank\" rel=\"noreferrer noopener\">configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP)<\/a>.<\/p>\n<p>Administrators can quickly verify their exposure by checking their NetScaler configuration for the specific string\u00a0add authentication samlIdPProfile .*.<\/p>\n<p>The second vulnerability, CVE-2026-4368, is a race condition flaw that triggers a user session mixup. Session mixups can inadvertently transfer an active session belonging to one user to another, unintentionally exposing sensitive information or granting access.<\/p>\n<p>This issue is triggered when the appliance operates as a Gateway (including SSL VPN, ICA Proxy, CVPN, and RDP Proxy) or as an <a href=\"https:\/\/cybersecuritynews.com\/citrix-netscaler-hackers-webshells\/\" target=\"_blank\" rel=\"noreferrer noopener\">Authentication, Authorization, and Auditing (AAA) virtual server.<\/a><\/p>\n<p>Configuration files containing\u00a0add authentication vserver .*\u00a0or\u00a0add vpn vserver .*\u00a0indicate an exposed deployment. These vulnerabilities exclusively impact customer-managed NetScaler ADC and Gateway systems.<\/p>\n<p>Cloud environments utilizing Citrix-managed cloud services or Citrix-managed Adaptive Authentication are not at risk, as the vendor has already applied the necessary infrastructure updates.<\/p>\n<p>To secure network infrastructure, cybersecurity teams must immediately <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696300&amp;articleURL=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_3055_and_CVE_2026_4368\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">upgrade affected appliances to the latest supported firmware versions.<\/a><\/p>\n<p>The flaws were identified during internal security reviews by Cloud Software Group, and there are currently no indicators of active exploitation in the wild.<\/p>\n<p>Regardless, the critical nature of the memory overread vulnerability necessitates rapid patching and vigilant monitoring of session integrity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/citrix-netscaler-and-gateway-vulnerabilities\/\">Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/citrix-netscaler-and-gateway-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information Cloud Software Group has issued a critical security bulletin detailing two newly discovered vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances. These flaws, tracked as CVE-2026-3055 and CVE-2026-4368, could allow remote attackers to leak sensitive information or cause user session mixups. Network [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,416],"tags":[130],"class_list":["post-11655","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11655"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11655"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11655\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}