INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix NetScaler Critical Vulnerability Exploit Found

| 2026-03-24 15:15 CRITICAL HIGH
Executive Summary AI-generated
The company's critical out-of-bounds read vulnerability, CVE-2026-3055, affects NetScaler ADC and Gateway versions 14.1 before 14.1-66.59 due to a software version mismatch between the affected systems and Citrix's advisory. The flaw can be exploited by attackers seeking to gain unauthorized access through session hijacking.
Technical Mitigations AI-generated
* Use a secure protocol such as HTTPS or SFTP to encrypt data transmitted between the client and server. * Implement input validation checks on user-supplied data to prevent buffer overflows and other types of attacks. * Regularly update operating systems, applications, and firmware to ensure that known vulnerabilities are patched before they can be exploited. * Use a secure password management system to store and generate strong passwords for all accounts.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt Typhoon CVE-2025-6543CVE-2025-6543 CVE-2025-7775CVE-2025-7775 CVE-2023-4966CVE-2023-4966 CVE-2025-5777CVE-2025-5777 CVE-2026-3055CVE-2026-3055 CVE-2026-4368CVE-2026-4368
Target & Sectors
Global Scope
Incident Timeline
March 23
Threat actors used a vulnerability in NetScaler ADC and Gateway versions 14.1 before 14.1-66.59 to target systems configured as SAML Identity Providers (SAPs).
vulnerability CVE-2026-3055
infrastructure 14.1
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1-37
organisation CVE-2026
organisation NetScaler ADC
organisation NetScaler ADC FIPS
organisation NetScaler
general_metric 14.1 versions
general_metric 13.1 NetScaler ADC
2026-3055
Threat actors used a software update to target Citrix NetScaler systems vulnerable to CVE 2026-3055.
infrastructure 14.1-60
organisation Global Deny List
financial 60.57 firmware builds
tactic T1592.002 - Software
Mar 24, 2026
Threat actors exploited a previously unknown vulnerability in Citrix's NetScaler product to gain unauthorized access.
2026-03-24
Citrix released security updates to address two vulnerabilities in its NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application.
infrastructure 9.3
organisation Citrix ADC
organisation CVSS
organisation CVE-2026
infrastructure 14.1
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1-37
organisation NetScaler ADC
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
infrastructure 13.1.37
infrastructure 14.1.60
infrastructure 13.1 FIPS
organisation ICA
organisation AAA
organisation NetScaler
organisation the Cloud
infrastructure 7.7
organisation SSL VPN
organisation NetScaler Application
organisation NetScaler Gateway
organisation Vulnerability / Enterprise Security
organisation NetScaler ADC
organisation NetScaler Configuration
organisation the Global Deny List
organisation NetScaler Console
organisation PoC
organisation AAA Vserver
organisation Shutterstock.com
threat_actor Salt Typhoon
organisation CVE-2023-4966
organisation CVE-2025-6543
organisation CVE-2025-7775
organisation Citrix Bleed
organisation CVE-2025
organisation SecurityAffairs
organisation The Hacker News
organisation the NetScaler Configuration
organisation NetScalers
Tactical Metrics
Metrics
infrastructure
​14.1
Software Version
Metrics
infrastructure
​14.1-66
Software Version
Metrics
infrastructure
​13.1
Software Version
Metrics
infrastructure
​13.1-62
Software Version
Metrics
infrastructure
​13.1-37
Software Version
Metrics
infrastructure
​13.1-FIPS
Software Version
Metrics
infrastructure
​13.1-NDcPP
Software Version
Metrics
infrastructure
​13.1.37
Software Version
Metrics
infrastructure
​14.1.60
Software Version
Metrics
infrastructure
13
Fips
Metrics
infrastructure
​14.1-60
Software Version
Metrics
financial
61
Firmware Builds
Metrics
infrastructure
​9.3
Software Version
Metrics
infrastructure
​7.7
Software Version
Intelligence Sources