LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3055 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 31, 2026

Published: March 23, 2026Updated: March 31, 2026

Overview

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 4335.1%(Probability of exploitation in next 30 days)

Social Media Activity(1 post)

Taggart :ifin:
Taggart :ifin:
@mttaggart
Apr 19, 2026

Useful explainer on the latest Citrix shenanigans, including verifying exposure and hunting/forensics recommendations https://www.picussecurity.com/resource/blog/cve-2026-3055-cve-2026-4368-inside-the-netscaler-citrixbleed-3-memory-overread

View original post

Details

CVE ID
CVE-2026-3055
Severity
Critical
CVSS Score
9.8
EPSS
4335.1%
Nuclei
Available
Social Posts
1

EPSS Score

4335.1%Probability of exploitation in the next 30 days

Nuclei Template

View Nuclei Template