By Carly Page
Publication Date: 2026-03-30 13:49:00
In-the-wild exploitation of a critical Citrix NetScaler bug has begun less than a week after disclosure, with researchers warning that attackers are already poking and pillaging vulnerable boxes.
Last week, Citrix pushed fixes for CVE-2026-3055, a 9.3-rated out-of-bounds read identified internally. The description sounded dry enough, but to anyone with scars from CitrixBleed and CitrixBleed2, the phrase “memory overread” set off alarm bells.
Those bells didn’t ring for long before someone answered the door. Threat intelligence outfit watchTowr says it saw reconnaissance traffic hitting vulnerable NetScaler instances by Friday, and by Sunday, it said it had evidence of active exploitation.
“Before we move on, we need to say something clearly: in-the-wild exploitation has begun,” the researchers wrote, pointing to honeypot data they said showed activity from infrastructure previously linked to threat actors as…



