Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Citrix NetScaler ADC and Gateway are affected by CVE-2026-3055, a critical vulnerability due to insufficient input validation during SAML authentication, leading to memory overread. Exploitation attempts have surged, with FortiGuard reporting over 2,000 blocked attacks daily, primarily targeting SAM...
On September 4, 2026, it was reported that threat actors are actively targeting a critical authentication bypass vulnerability in Citrix NetScaler, tracked as CVE-2026-19490. This flaw allows unauthenticated attackers to bypass authentication controls on affected NetScaler ADC and Gateway deployment...
Cloud Software Group has identified and patched two critical vulnerabilities in Citrix NetScaler ADC and Gateway products. The vulnerabilities, tracked as CVE-2026-3055, allow unauthenticated remote attackers to exploit memory overreads and potentially leak sensitive data. Organizations using these...
In the first half of 2026, multiple organizations were targeted by an Initial Access Broker exploiting the CitrixBleed 2 vulnerability (CVE-2025-5777). Attackers gained access through the Citrix NetScaler gateway, escalating privileges and creating rogue administrator accounts. The most advanced att...