INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix NetScaler Critical Vulnerability Exploit Found

| 2026-03-24 15:15 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The company's critical out-of-bounds read vulnerability, CVE-2026-3055, affects NetScaler ADC and Gateway versions 14.1 before 14.1-66.59 due to a software version mismatch between the affected systems and Citrix's advisory. The flaw can be exploited by attackers seeking to gain unauthorized access through session hijacking.
Technical Mitigations AI-generated
* Use a secure protocol such as HTTPS or SFTP to encrypt data transmitted between the client and server. * Implement input validation checks on user-supplied data to prevent buffer overflows and other types of attacks. * Regularly update operating systems, applications, and firmware to ensure that known vulnerabilities are patched before they can be exploited. * Use a secure password management system to store and generate strong passwords for all accounts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

14.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon CVE-2025-6543CVE-2025-6543 CVE-2025-7775CVE-2025-7775 CVE-2023-4966CVE-2023-4966 CVE-2025-5777CVE-2025-5777 CVE-2026-3055CVE-2026-3055 CVE-2026-4368CVE-2026-4368
Target & Sectors
Global Scope
Incident Timeline
March 23
Threat actors used a vulnerability in NetScaler ADC and Gateway versions 14.1 before 14.1-66.59 to target systems configured as SAML Identity Providers (SAPs).
vulnerability CVE-2026-3055
infrastructure 14.1
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1-37
organisation CVE-2026
organisation NetScaler ADC
organisation NetScaler ADC FIPS
organisation NetScaler
general_metric 14.1 versions
general_metric 13.1 NetScaler ADC
2026-3055
Threat actors used a software update to target Citrix NetScaler systems vulnerable to CVE 2026-3055.
infrastructure 14.1-60
organisation Global Deny List
financial 60.57 firmware builds
tactic T1592.002 - Software
Mar 24, 2026
Threat actors exploited a previously unknown vulnerability in Citrix's NetScaler product to gain unauthorized access.
2026-03-24
Citrix released security updates to address two vulnerabilities in its NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application.
infrastructure 9.3
organisation Citrix ADC
organisation CVSS
organisation CVE-2026
infrastructure 14.1
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1-37
organisation NetScaler ADC
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
infrastructure 13.1.37
infrastructure 14.1.60
infrastructure 13.1 FIPS
organisation ICA
organisation AAA
organisation NetScaler
organisation the Cloud
infrastructure 7.7
organisation SSL VPN
organisation NetScaler Application
organisation NetScaler Gateway
organisation Vulnerability / Enterprise Security
organisation NetScaler ADC
organisation NetScaler Configuration
organisation the Global Deny List
organisation NetScaler Console
organisation PoC
organisation AAA Vserver
organisation Shutterstock.com
threat_actor Salt Typhoon
organisation CVE-2023-4966
organisation CVE-2025-6543
organisation CVE-2025-7775
organisation Citrix Bleed
organisation CVE-2025
organisation SecurityAffairs
organisation The Hacker News
organisation the NetScaler Configuration
organisation NetScalers
Tactical Metrics
Metrics
infrastructure
​14.1
Software Version
Metrics
infrastructure
​14.1-66
Software Version
Metrics
infrastructure
​13.1
Software Version
Metrics
infrastructure
​13.1-62
Software Version
Metrics
infrastructure
​13.1-37
Software Version
Metrics
infrastructure
​13.1-FIPS
Software Version
Metrics
infrastructure
​13.1-NDcPP
Software Version
Metrics
infrastructure
​13.1.37
Software Version
Metrics
infrastructure
​14.1.60
Software Version
Metrics
infrastructure
13
Fips
Metrics
infrastructure
​14.1-60
Software Version
Metrics
financial
61
Firmware Builds
Metrics
infrastructure
​9.3
Software Version
Metrics
infrastructure
​7.7
Software Version
Intelligence Sources