Citrix ’s recent security update announcement highlights serious issues regarding corporate infrastructure protection. Two new vulnerabilities identified in NetScaler ADC and NetScaler Gateway are causing concern, with one of them being classified as critical. The problem is primarily in the handling of sensitive data , highlighting once again the importance of responding promptly to cybersecurity issues.

Analysis of vulnerability CVE-2026-3055 and its impacts
The first and most dangerous vulnerability, codenamed CVE-2026-3055 and rated 9.3 on the CVSS scoring system, is related to insufficient input validation. This technical gap allows memory overread, allowing remote attackers to gain access to sensitive information. Although exploitation is not possible in all cases, the threat becomes real when the device is configured as a SAML Identity Provider.
See also: Citrix: NetScaler vulnerability used for DoS attacks
This means that many default installations remain secure, but organizations with customized settings may be at risk. The company's recommendation to administrators is clear: immediate review of settings to identify the presence of relevant parameters that could expose systems.
The second threat: CVE-2026-4368
The second vulnerability, CVE-2026-4368, with a score of 7.7, concerns a race condition that leads to session mixup. In practical terms, this means that a user could gain access to another user's data, undermining security and privacy.
Exploiting this vulnerability requires the system to function as either an access gateway or an Authentication, Authorization, and Accounting (AAA) server . Administrators are advised to consider whether their infrastructure functions as AAA servers or VPN gateways, as these configurations increase the risk .
See also: Citrix patches critical vulnerability in NetScaler Console and NetScaler Agent

Why NetScaler vulnerabilities remain a timeless target
NetScaler systems have been a prime target for cyberattacks for years. The reason is simple: they are on the “front line” of access to corporate networks. When an attacker manages to compromise such a system, they often gain access to the entire infrastructure.
History has shown that similar security gaps do not remain unexploited for long. Attacks from previous years have leveraged comparable vulnerabilities, causing extensive data leaks and significant operational impacts.
Expert commentary and concern in the cybersecurity community
Benjamin Harris, head of watchTowr, stressed that the new vulnerability is strongly reminiscent of previous incidents such as Citrix Bleed. According to him, this similarity is not at all reassuring, as such weaknesses have proven to be particularly dangerous in the past.
His statement underscores a key point: attacks on such infrastructure are not theoretical. Instead, they pose an immediate and realistic threat, especially when organizations delay implementing updates.
See also: Amazon: Cisco ISE and Citrix NetScaler zero-day exploit

The need for immediate action and preventive measures
Although so far there are no confirmed attacks exploiting these specific vulnerabilities, experts warn that this could change at any moment. The delay in installing updates is one of the main reasons for the success of cyber attacks.
Organizations are urged to act immediately by applying available patches and performing security audits on their configurations. At the same time, adopting practices such as continuous monitoring and the principle of least access can significantly reduce the risk.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This case serves as yet another reminder that cybersecurity is not a static process but a continuous battle, where response speed often determines the outcome.
