CVE-2026-3055: Citrix NetScaler SAML IDP Memory Overread: CitrixBleed 3 Under Active Exploitation

By Parth Shukla · 2026-04-16

CVE-2026-3055 in Citrix NetScaler: SAML IDP memory overread (CitrixBleed 3), KEV-listed and actively exploited. Detect and patch now.

#cve #citrix #netscaler #oob-read #kev

Frequently asked questions

What is CVE-2026-3055?

CVE-2026-3055 is an out-of-bounds read (CWE-125) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a SAML Identity Provider (IDP). Insufficient input validation on a field in the SAML flow causes the appliance to read past the end of an allocated buffer and return that memory — including uninitialized bytes and leftover session data — back to the attacker in the HTTP response.

Is CVE-2026-3055 being actively exploited?

Yes. CISA added CVE-2026-3055 to the KEV catalog on March 30, 2026, only a week after Citrix published the bulletin, with a federal remediation deadline of April 2 — a three-day window that signals observed in-the-wild exploitation at scale.

Am I exposed to CVE-2026-3055?

The flaw is only exploitable when the appliance is configured as a SAML IDP or SAML SP with IDP functionality enabled. The affected builds are:

How do I fix CVE-2026-3055?

These branches are end-of-life and will not receive a patch. Move to a supported branch as part of the same change window.

Check your own attack surface with Pinaka