Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks

Delve suspends demos, Insight Partners removes investment posts due to ‘fake compliance’ allegations

Emile Michael, now a senior Pentagon official, says he will never forgive the Uber investors who ousted him and Kalanick.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks
Identity

Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks

By March 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 24, 2026Vulnerabilities / Enterprise Security

Citrix has released security updates that address two vulnerabilities in NetScaler ADC and NetScaler Gateway that contain critical flaws that can be exploited to leak sensitive data from applications.

The vulnerabilities are listed below –

CVE-2026-3055 (CVSS score: 9.3) – Insufficient input validation leading to memory over-read CVE-2026-4368 (CVSS score: 7.7) – Race condition leading to user session disruption

Cybersecurity firm Rapid7 said CVE-2026-3055 refers to an out-of-bounds read that could be exploited by an unauthenticated, remote attacker to leak potentially sensitive information from the appliance’s memory.

However, for the exploitation to be successful, the Citrix ADC or Citrix Gateway appliance must be configured as a SAML identity provider (SAML IDP). That is, the default configuration is not affected. To determine if a device is configured as a SAML IDP profile, Citrix recommends customers inspect the string “add authentication samlIdPProfile .*” specified in the NetScaler configuration.

CVE-2026-4368, on the other hand, requires the appliance to be configured as a gateway (i.e., SSL VPN, ICA Proxy, CVPN, and RDP Proxy) or an Authentication, Authorization, and Accounting (AAA) server. Customers can check their NetScaler configuration to see if their device is configured as one of the following nodes:

AAA Virtual Server – Add an authentication vserver. * Gateway – Add vpn vserver. *

This vulnerability affects NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. For optimal protection, users are encouraged to apply the latest updates as soon as possible.

Although there is no evidence that this flaw has been exploited, the security flaw in NetScaler devices has been repeatedly exploited by threat actors (CVE-2023-4966, aka Citrix Bleed, CVE-2025-5777, aka Citrix Bleed 2, CVE-2025-6543, and CVE-2025-7775), making it imperative for users to take precautions. Update the instance.

“CVE-2026-3055 allows an unauthenticated attacker to leak and read sensitive memory from a NetScaler ADC deployment. If this sounds familiar, that’s because it is. This vulnerability is suspiciously similar to Citrix Bleed and Citrix Bleed 2, which continue to be traumatic events for many,” said Benjamin Harris, CEO and founder of watchTowr, The Hacker. told News.

“NetScaler is a critical solution that continues to be targeted for initial access to enterprise environments. Although this advisory has just been published, defenders must act quickly. Anyone running an affected version should apply the patch as soon as possible. The likelihood of imminent exploitation is very high.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDelve suspends demos, Insight Partners removes investment posts due to ‘fake compliance’ allegations

Related Posts

North Korean hackers exploit VS Code autorun tasks to deploy StoatWaffle malware

March 23, 2026

CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

March 23, 2026

We discovered eight attack vectors within AWS Bedrock. Here’s what an attacker can do with them

March 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Citrix asks to patch critical flaw in NetScaler that could lead to unauthenticated data leaks

Delve suspends demos, Insight Partners removes investment posts due to ‘fake compliance’ allegations

Emile Michael, now a senior Pentagon official, says he will never forgive the Uber investors who ousted him and Kalanick.

Someone has released an exploit kit that can hack millions of iPhones.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.