Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you — not vendor summaries written a week late.

Rapid Reaction – Citrix NetScaler ADC and NetScaler Gateway Memory Overread Vulnerability (CVE-2026-3055)

Citrix has released patches for CVE-2026-3055, a Memory Overread vulnerability affecting NetScaler ADC and NetScaler Gateway appliances, with a CVSS v4 base score of 9.3. Citrix states this vulnerability was identified internally, with no known in-the-wild exploitation at time of disclosure. watchTowr Instinct assesses in-the-wild exploitation as imminent, based on the vulnerability class, prior and…

Citrix has released patches for CVE-2026-3055, a Memory Overread vulnerability affecting NetScaler ADC and NetScaler Gateway appliances, with a CVSS v4 base score of 9.3.

Citrix states this vulnerability was identified internally, with no known in-the-wild exploitation at time of disclosure. watchTowr Instinct assesses in-the-wild exploitation as imminent, based on the vulnerability class, prior and sustained attacker interest in NetScaler products, and the direct relevance of memory disclosure vulnerabilities to the enterprise breach scenarios attackers are actively pursuing.

This is the same vulnerability class as CitrixBleed and CitrixBleed2, stories the industry knows unfortunately well.

watchTowr triggered our Rapid Reaction capability to determine exposure across client environments, giving teams the time they need to respond before exploitation begins.

If you need urgent help assessing your exposure, contact us here.

What Is the Vulnerability

CVE-2026-3055 is an out-of-bounds read vulnerability that Citrix describes as a Memory Overread issue.

⚠️ Citrix states that NetScaler ADC or NetScaler Gateway must be configured as a SAML IdP to be vulnerable. That precondition narrows scope, but this configuration is common across large enterprise environments.

What Is Affected

NetScaler ADC and NetScaler Gateway are widely deployed enterprise application delivery and remote access products, typically positioned at the Internet-facing edge of enterprise environments.

Product NameAffected Versions
NetScaler ADCAll versions prior to 14.1-66.59, 13.1-62.23, and 13.1-37.262 FIPS and NDcPP
NetScaler GatewayAll versions prior to 14.1-66.59 and 13.1-62.23

What Should You Do

  1. Determine whether your NetScaler instances are configured as SAML IdPs
  2. Identify which instances are unpatched and Internet-facing
  3. Patch immediately, prioritizing Internet-exposed instances first
Product NamePatched Version(s)
NetScaler ADC14.1-66.59 and later, 13.1-62.23 and later, 13.1-37.262 FIPS and NDcPP and later
NetScaler Gateway14.1-66.59 and later, 13.1-62.23 and later

How watchTowr Helps

The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and tracking external exposure across enterprise environments. The following capabilities were utilized for CVE-2026-3055:

  • watchTowr Instinct assessed CVE-2026-3055 as high-likelihood for in-the-wild exploitation
  • watchTowr’s Adversary Sight engine identified NetScaler ADC and NetScaler Gateway instances across client environments and assessed exposure
  • watchTowr’s Attacker Eye, our global honeypot network, is monitoring for in-the-wild exploitation activity as it emerges
  • Rapid Reaction was executed across the watchTowr client base, identifying exposure and giving teams the time they need to act

When exploitation happens in hours, watchTowr delivers what no one else can: time to respond. Request a demo

If you are a watchTowr client

Rapid Reaction has already run against your validated attack surface. Affected assets are flagged in your console with confirmed exploitability, and Active Defense mitigation rules were made available for your edge controls within the hour. You do not need to open a ticket.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

On this page

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.