CISA Issues Urgent Patch Warning for Critical Citrix NetScaler Vulnerability Actively Exploited in the Wild

CISA has added a critical Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild abuse. Federal agencies have until April 2 to patch — here is everything your organization needs to know.

Salma Mubarak
Cloud Security & AI Security Contributor4 min read
A digital security illustration representing the critical Citrix NetScaler vulnerability CVE-2026-3055 flagged by CISA for immediate patching.

A digital security illustration representing the critical Citrix NetScaler vulnerability CVE-2026-3055 flagged by CISA for immediate patching.

A critical vulnerability in Citrix NetScaler ADC and Gateway is being actively exploited in the wild — and the US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent patch warning, giving federal agencies just days to apply the fix.

The vulnerability, tracked as CVE-2026-3055 and assigned a severity score of 9.3 out of 10, affects NetScaler ADC and NetScaler Gateway when configured as a SAML Identity Provider. Active exploitation has been confirmed since at least March 27, 2026, with approximately 30,000 NetScaler ADC and 2,000 Gateway instances currently exposed globally.

What is the vulnerability and how does it work

The flaw is an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway. When the software is configured as a SAML IDP, the bug enables memory overread — meaning attackers can access regions of memory they should have no access to, potentially exposing sensitive data stored there.
In practical terms, this allows threat actors to access sensitive information and execute unauthorized actions on affected systems. Depending on how the vulnerable software is deployed, the bug can also be chained with other flaws to escalate access and gain broader control over the affected environment.

Active exploitation confirmed

Multiple commercial cybersecurity firms have independently confirmed seeing this vulnerability abused in the wild — not just CISA. Security firm watchtower reported observing reconnaissance activity over the weekend, targeting vulnerable endpoints. These probes typically precede broader attack campaigns, and watchTowr confirmed active exploitation a day later.

"In-the-wild exploitation has begun, with evidence from our honeypot network showing exploitation from known threat actor source IPs as of March 27," watchTowr said.

Several researchers have also noted that the attack patterns observed closely resemble those seen in CitrixBleed and CitrixBleed2 — two major Citrix vulnerabilities from recent years that caused widespread disruption across enterprise environments globally.

Who is affected

The vulnerability affects the following versions of Citrix NetScaler ADC and Gateway:

  • Versions older than 14.1-60.58
  • Versions older than 13.1-662.23
  • Versions older than 13.1-37.262 on FIPS and NDcPP configurations

Organizations running any of these versions in a SAML IDP configuration should treat this as an immediate priority.

The patch — and the deadline

Citrix has released fixed versions addressing CVE-2026-3055:

  • NetScaler ADC / Gateway 14.1-66.59 or later
  • NetScaler ADC / Gateway 13.1-62.23 or later
  • NetScaler ADC 13.1-FIPS / NDcPP 13.1-37.262 or later

CISA has ordered all Federal Civilian Executive Branch agncies to apply the patch by April 2, 2026 — an exceptionally tight deadline that underlines the severity and urgency of the threat. While this mandate applies specifically to US federal agencies, the same patching urgency applies to any enterprise running affected versions anywhere in the world.

Why GCC and MENA organizations should act now

Citrix NetScaler ADC and Gateway are widely deployed across enterprise and government environments throughout the GCC. Organizations in Saudi Arabia, the UAE, Qatar, and Kuwait — many of which are running large-scale digital infrastructure as part of national transformation programs — are likely running affected versions.

Regulatory bodies including UAE-CERT and Saudi Arabia's National Cybersecurity Authority typically mirror CISA advisories closely. Organizations in the region should not wait for a local advisory before acting — the global exploitation activity already underway makes immediate patching essential.

Is your business running Citrix NetScaler?

If your organization uses Citrix NetScaler ADC or Gateway — or you are not sure — now is the time to find out. Ask your IT team or technology partner to confirm whether your systems are running an affected version and whether they are configured as a SAML Identity Provider. If they are, getting the latest patch applied should be your top priority this week.

For businesses without a dedicated security team, this is exactly the kind of vulnerability that can go unnoticed until it is too late. A quick conversation with your technology partner today could prevent a serious breach tomorrow.

Salma Mubarak

Cloud Security & AI Security Contributor

Salma is a cloud security architect and AI risk analyst specializing in DevSecOps, SaaS security, and infrastructure protection. She focuses on identifying cloud misconfigurations, AI vulnerabilities, and implementing zero-trust security frameworks for modern organizations.

At MENA Cyber Wire, Salma breaks down complex cybersecurity and AI risk concepts into clear, practical insights for founders, IT managers, and security professionals across the MENA region.

Intelligence Focus Areas

Cybersecurity Threats 2026Compliance & Patch Policy