Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat 30.03.2026

Researchers at watchTowr have confirmed that a critical Citrix NetScaler vulnerability, CVE-2026-3055, is already being actively exploited in the wild, with attackers beginning reconnaissance as early as Friday, March 27, 2026, and evidence of exploitation by Sunday. This out-of-bounds read flaw, rated 9.3, allows attackers to send a crafted request that causes NetScaler to access and return sensitive memory contents, potentially including session tokens and credentials. The vulnerability shares similarities with previous memory handling issues like CitrixBleed2 and is believed to encompass multiple closely related memory leaks bundled under a single identifier. The UK's National Cyber Security Centre has issued a warning, urging organizations to patch their NetScaler ADC and Gateway deployments due to their critical position in identity paths.















