Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems
Cloud Software Group has issued critical security patches for NetScaler ADC and NetScaler Gateway , addressing two vulnerabilities that could allow unauthenticated remote attackers to compromise affected systems. Organizations using customer-managed…
Cloud Software Group has issued critical security patches for NetScaler ADC and NetScaler Gateway , addressing two vulnerabilities that could allow unauthenticated remote attackers to compromise affected systems. Organizations using customer-managed deployments are advised to apply these updates immediately.
CVE-2026-3055: Critical Out-of-Bounds Read via SAML IDP
The vulnerability, CVE-2026-3055, has a CVSS v4.0 base score of 9.3 and is considered critical. It results from insufficient input validation, leading to a memory overread condition. The flaw is exploitable without authentication, user interaction, or specific preconditions, except that the appliance must be configured as a SAML Identity Provider (IDP).
This issue was identified internally by Cloud Software Group and has not been actively exploited. However, due to its critical nature, it requires immediate attention. Administrators can verify exposure by checking for the string add authentication samlIdPProfile .* in the NetScaler configuration.
CVE-2026-4368: Race Condition Causing Session Mixup
The second vulnerability, CVE-2026-4368, scores 7.7 on the CVSS v4.0 scale and involves a race condition that can lead to user session mixup. It affects appliances configured as a Gateway or as an AAA virtual server. Exploitation requires low-privilege authentication and an adjacent timing condition, potentially compromising session confidentiality and integrity.
Exposure can be identified by checking configurations for add authentication vserver . or add vpn vserver . .
Organizations using customer-managed deployments are advised to apply these updates immediately.
The vulnerabilities affect the following versions:
CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59; 13.1 before 13.1-62.23; FIPS/NDcPP before 13.1-37.262 CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54
Cloud Software Group recommends upgrading to:
NetScaler ADC and Gateway 14.1-66.59 or later NetScaler ADC and Gateway 13.1-62.23 or later NetScaler ADC 13.1-FIPS / NDcPP 13.1.37.262 or later
Note that this advisory applies exclusively to customer-managed deployments. Citrix-managed cloud services and Adaptive Authentication instances have been updated by Cloud Software Group. Unpatched systems represent a significant attack surface, particularly in enterprise environments where NetScaler ADC and Gateway are widely deployed. Security teams should prioritize deploying patches, especially for SAML IDP-configured appliances due to the critical score of CVE-2026-3055.
Based on reporting by Cyber Security News.
