INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Citrix NetScaler Vulnerability Exploited in the Wild

| 2026-03-31 07:05 HIGH HIGH
Executive Summary AI-generated
The Citrix vulnerability, CVE-2026-3055, has been identified as a critical threat to the security of U.S. government agencies and private sector organizations. The flaw allows remote attackers to steal sensitive information from Citrix ADC or Citrix Gateway appliances configured as SAML identity providers. This could potentially enable full takeover of unpatched NetScaler appliances. CISA has ordered federal civilian executive branch agencies to secure vulnerable Citrix appliances by Thursday, April 2, and urged all defenders, including those in the private sector, to prioritize patching for CVE-2026-3055 and secure their organizations' devices as soon as possible. The vulnerability was already being abused in the wild days after Citrix issued patches, warning that attackers can use it to steal admin authentication session IDs potentially enabling a full takeover of unpatched NetScaler appliances.
Technical Mitigations AI-generated
* Implement input validation checks on all user inputs to prevent memory overread and unauthorized access. * Regularly update and patch Citrix NetScaler appliances with the latest security updates, including CVE-2026-3055 patches. * Configure Citrix ADC or Gateway instances as SAML identity providers (IDPs) with proper authentication mechanisms in place to minimize potential vulnerabilities. * Monitor system logs for suspicious activity and implement automated pentesting and diagnostic tools to detect potential exploitation attempts.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-3055CVE-2026-3055
Target & Sectors
Global Scope
Incident Timeline
October 2023
Threat actors used a newly discovered Citrix vulnerability to breach high-profile tech firms such as Boeing.
attribution Citrix Bleed
attribution Boeing
August 2025
CISA ordered federal agencies to patch the Citrix flaw by Thursday due to its actively exploited status.
attribution CISA
March 23
Threat actors used a newly discovered vulnerability in Citrix's NetScaler Application Delivery Controller and NetScaler Gateway to target systems with specific versions of the software.
vulnerability CVE-2026-3055
organisation CitrixBleed
organisation NetScaler Application
organisation NetScaler Gateway
organisation CVSS v4.0
general_metric 3055 CVE-2026
organisation NetScaler
infrastructure 14.1
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1-37
organisation NetScaler ADC
organisation NetScaler ADC FIPS
organisation Citrix’s
general_metric 14.1 versions
general_metric 13.1 NetScaler ADC
infrastructure 13.1 ADC FIPS
tactic T1592.002 - Software
March 27
Threat actors used a known vulnerability in NetScaler ADC and Gateway to exploit the Citrix flaw.
vulnerability CVE-2026-3055
organisation CVE-2026
organisation Defused
March 28
Threat actors used a newly discovered vulnerability in Citrix to target systems.
vulnerability CVE-2026-3055
organisation Honeypot Activity Shows CVE-2026
March 29
The US Cybersecurity and Infrastructure Security Agency (CISA) ordered the federal government to patch a newly discovered vulnerability in Citrix by Thursday, March 29.
vulnerability CVE-2026-3055
2026-3055
Threat actors used a patch for actively exploited Citrix vulnerability to target systems running 14.1-60.57 firmware builds with Global Deny List signatures for CVE 2026-3055 on or after March 23, 2026.
tactic T1592.002 - Software
infrastructure 14.1-60
organisation Global Deny List
financial 60.57 firmware builds
2026-03-31
Citrix's NetScaler appliances were urged to be patched by Thursday due to an actively exploited vulnerability, CVE-2026-3055.
organisation CVE-2026
organisation the Cloud
organisation ADC
organisation IDP
organisation Citrix ADC
organisation Watchtowr
organisation NetScaler
organisation Gateway
organisation BOD
infrastructure 14.1-66
infrastructure 13.1
infrastructure 13.1-62
infrastructure 13.1 ADC FIPS
infrastructure 13.1-FIPS
infrastructure 13.1-NDcPP
infrastructure 13.1.37
infrastructure 14.1.60
organisation Critical Citrix NetScaler Vulnerability Exploited
organisation NetScaler Configuration
organisation SAMLRequest
organisation the Global Deny List
organisation NetScaler Console
Thursday, April 2
CISA ordered the Federal Civilian Executive Branch agencies to patch the CVE-2026-3055 vulnerability in Citrix NetScaler ADC instances by Thursday, April 2.
vulnerability CVE-2026-3055
attribution NetScaler ADC
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
​14.1
Software Version
Metrics
infrastructure
​14.1-66
Software Version
Metrics
infrastructure
​13.1
Software Version
Metrics
infrastructure
​13.1-62
Software Version
Metrics
infrastructure
​13.1-37
Software Version
Metrics
infrastructure
13
Adc Fips
Metrics
infrastructure
​13.1-FIPS
Software Version
Metrics
infrastructure
​13.1-NDcPP
Software Version
Metrics
infrastructure
​13.1.37
Software Version
Metrics
infrastructure
​14.1.60
Software Version
Metrics
infrastructure
​14.1-60
Software Version
Metrics
financial
61
Firmware Builds
Intelligence Sources
Infosecurity-Magazine 2026-03-30