By @AlizTheHax0r
Publication Date: 2026-03-29 20:07:00
Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055?
While we’ve been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately identify exploitable Citrix NetScaler appliances across the watchTowr client base, we couldn’t help but wonder: could there be more hiding in Citrix’s patches?
These thoughts, and worse, naturally come to us at 6 am on a Sunday morning.
Welcome back to the hellscape, and yet another watchTowr Labs blog post.

What we can confidently conclude, post-analysis, is that CVE-2026-3055 is not one singular memory overread vulnerability. In fact, this CVE ID has been assigned to at least two memory overread vulnerabilities, affecting the following endpoints:
- /saml/login
- /wsfed/passive?wctx
Some would say this is disingenuous, Citrix.
Unrelated, and without comment, we leave a screenshot of part of CISA’s Secure By Design pledge,…



