Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)

Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)

By @AlizTheHax0r
Publication Date: 2026-03-29 20:07:00

Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055?

While we’ve been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately identify exploitable Citrix NetScaler appliances across the watchTowr client base, we couldn’t help but wonder: could there be more hiding in Citrix’s patches?

These thoughts, and worse, naturally come to us at 6 am on a Sunday morning.

Welcome back to the hellscape, and yet another watchTowr Labs blog post.

What we can confidently conclude, post-analysis, is that CVE-2026-3055 is not one singular memory overread vulnerability. In fact, this CVE ID has been assigned to at least two memory overread vulnerabilities, affecting the following endpoints:

  • /saml/login
  • /wsfed/passive?wctx

Some would say this is disingenuous, Citrix.

Unrelated, and without comment, we leave a screenshot of part of CISA’s Secure By Design pledge,…