Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Cloud Software Group has issued critical security patches for NetScaler ADC and NetScaler Gateway , addressing two vulnerabilities that could allow unauthenticated remote attackers to compromise affected systems. Organizations using customer-managed…

Cloud Software Group has issued critical security patches for NetScaler ADC and NetScaler Gateway , addressing two vulnerabilities that could allow unauthenticated remote attackers to compromise affected systems. Organizations using customer-managed deployments are advised to apply these updates immediately.

CVE-2026-3055: Critical Out-of-Bounds Read via SAML IDP

The vulnerability, CVE-2026-3055, has a CVSS v4.0 base score of 9.3 and is considered critical. It results from insufficient input validation, leading to a memory overread condition. The flaw is exploitable without authentication, user interaction, or specific preconditions, except that the appliance must be configured as a SAML Identity Provider (IDP).

This issue was identified internally by Cloud Software Group and has not been actively exploited. However, due to its critical nature, it requires immediate attention. Administrators can verify exposure by checking for the string add authentication samlIdPProfile .* in the NetScaler configuration.

CVE-2026-4368: Race Condition Causing Session Mixup

The second vulnerability, CVE-2026-4368, scores 7.7 on the CVSS v4.0 scale and involves a race condition that can lead to user session mixup. It affects appliances configured as a Gateway or as an AAA virtual server. Exploitation requires low-privilege authentication and an adjacent timing condition, potentially compromising session confidentiality and integrity.

Exposure can be identified by checking configurations for add authentication vserver . or add vpn vserver . .

Organizations using customer-managed deployments are advised to apply these updates immediately.
Harper Fairbanks · Thehackingpost

The vulnerabilities affect the following versions:

CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59; 13.1 before 13.1-62.23; FIPS/NDcPP before 13.1-37.262 CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54

Cloud Software Group recommends upgrading to:

Advertisement

NetScaler ADC and Gateway 14.1-66.59 or later NetScaler ADC and Gateway 13.1-62.23 or later NetScaler ADC 13.1-FIPS / NDcPP 13.1.37.262 or later

Note that this advisory applies exclusively to customer-managed deployments. Citrix-managed cloud services and Adaptive Authentication instances have been updated by Cloud Software Group. Unpatched systems represent a significant attack surface, particularly in enterprise environments where NetScaler ADC and Gateway are widely deployed. Security teams should prioritize deploying patches, especially for SAML IDP-configured appliances due to the critical score of CVE-2026-3055.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories