Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) – Help Net Security

Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-03-24 14:13:00

Citrix has fixed two vulnerabilities in NetScaler ADC and NetScaler Gateway, with the more serious flaw (CVE-2026-3055) potentially allowing attackers to extract active session tokens from the memory of affected devices.

Anil Shetty, senior VP of Engineering with Cloud Software Group (Citrix’s parent company), stated on Saturday that Cloud Software Group “is not aware of any unmitigated exploit available for either CVE 2026-3055 or CVE 2026-4368.”

Still, as both vulnerabilities can be exploited in low-complexity attacks and are in solutions that are often targeted by attackers, the company has urged customers to upgrade to a fixed version as soon as possible.

The vulnerabilities (CVE-2026-3055, CVE-2026-4368)

NetScaler ADC (application delivery controller) is a networking appliance used for improving the performance, security, and resiliency of applications.

NetScaler Gateway is a solution that allows users to safely access internal company resources (e.g., apps,…