CVE-2026-4368
CVE-2026-3055, with a CVSS score of 9.3 (Critical), is an Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread. The vulnerability could allow attackers to gain unauthorized access to sensitive information or systems by leveraging the memory overread flaw. It affects: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-66.59 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23 NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262 CVE-2026-4368, with a CVSS score of 7.7 (High), is a race condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup. This could allow one user to access another user's session on systems configured as a Gateway or AAA virtual server It affects: NetScaler ADC and NetScaler Gateway 14.1-66.54
EPSS 0.02% · 3.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citrix | NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.262 | |
| Citrix | NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-62.23 | |
| Citrix | NetScaler ADC and NetScaler Gateway 14.1-66.54 | |
| Citrix | NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-66.59 |
Timeline
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 23, 2026 PoC Published