Hackers Probe Citrix NetScaler Systems Ahead of Suspected CVE-2026-3055 Exploitation

Hackers Probe Citrix NetScaler Systems Ahead of Suspected CVE-2026-3055 Exploitation

By Divya
Publication Date: 2026-03-30 05:41:00

Cybersecurity researchers are warning organizations about imminent cyberattacks targeting a newly disclosed critical vulnerability in Citrix NetScaler ADC and Gateway appliances.

Threat intelligence firms watchTowr and Defused Cyber have uncovered active reconnaissance campaigns targeting CVE-2026-3055, a severe flaw that allows attackers to steal sensitive data.

With hackers actively scanning for exposed systems, organizations are urged to patch their appliances before these probes escalate into full-scale attack campaigns.

Telemetry captured data (Source: CSN)

Understanding CVE-2026-3055

Assigned a critical CVSS score of 9.3, CVE-2026-3055 is caused by insufficient input validation, which creates an out-of-bounds memory read condition, as reported by CSN.

For an appliance to be vulnerable, it must be specifically configured to operate as a SAML Identity Provider.

Because this identity setup is widely used in enterprise single sign-on environments to…