HomeSecurityCISA: Citrix NetScaler Vulnerability in the KEV List

CISA: Citrix NetScaler vulnerability in KEV Catalog

Organizations using Citrix infrastructure are on high alert after an urgent directive from the U.S. Cybersecurity and Infrastructure Security Administration (CISA). The agency has asked federal agencies to immediately proceed with security updates for Citrix NetScaler appliances due to a critical vulnerability that is already considered high risk. The vulnerability, listed as CVE-2026-3055 , has caught the attention of the cybersecurity community due to its technical similarities to previous serious threats, such as CitrixBleed and CitrixBleed2 .

Citrix NetScaler

This vulnerability is located in the way input validation is performed , allowing unauthorized remote attackers to gain access to sensitive information . Especially in cases where Citrix ADC and Gateway identity providers SAML devices act as , the risk increases significantly, as the path to interception of critical authentication data is opened.

Active exploitation and risk of complete breach

Although Citrix has already released security patches since March 23, researchers note that the vulnerability was not long in being exploited in practice. Cybersecurity firm Watchtowr reported that attackers exploited the gap within days of the updates being released, confirming that this is a particularly dangerous scenario.

See also: OpenAI fixes data extraction vulnerability in ChatGPT

Most worryingly, attackers can steal administrator authentication tokens, thereby gaining complete control over unpatched devices. In such cases, access is not limited to simple data monitoring, but can extend to full-scale breach of corporate networks.

Despite the indications of exploitation, Citrix has not officially confirmed any active large-scale attacks. However, experience from previous incidents shows that delaying the application of updates can be devastating for organizations managing critical infrastructure.

Thousands of exposed devices worldwide

According to data from the Shadowserver, tens of thousands of NetScaler appliances remain exposed online. Specifically, nearly 30,000 ADC appliances and over 2,300 Gateway instances are listed as accessible, but it is unclear how many of these have already been patched or remain vulnerable.

CISA: Citrix NetScaler vulnerability in KEV Catalog

This uncertainty intensifies the risk, as attackers can massively exploit systems that have not received the necessary patches. In environments where identity and access services are a critical component of operations, such a breach could lead to widespread data leaks or even ransomware attacks.

See also: Fortinet Forticlient EMS: Critical vulnerability used in attacks

CISA's response and guidance to organizations

CISA has added vulnerability CVE-2026-3055 to the List of Known Exploitable Vulnerabilities (KEV), triggering strict compliance procedures for federal agencies. Through Binding Directive BOD 22-01, organizations are urged to proceed with immediate remediation (April 2) or, if this is not feasible, to discontinue use of affected systems.

While the directive primarily targets U.S. government agencies, CISA has issued a clear recommendation to the private sector to move with the same speed. The agency warns that such vulnerabilities are a common entry point for malicious actors, especially in targeted, high-value attacks.

A familiar threat with a new face

The CVE-2026-3055 case adds to a long list of security issues that have plagued Citrix platforms in recent years. CISA has already listed dozens of the company's vulnerabilities as being actively exploited, with several of them being used in ransomware attacks and targeted breaches of large organizations.

See also: Smart Slider 3 WordPress: Vulnerability affects thousands of sites

CISA: Citrix NetScaler vulnerability in KEV Catalog

The fact that the new vulnerability bears similarities to previous incidents, such as CitrixBleed, reinforces the concern that attackers are reusing proven techniques with high success rates. This makes the need for constant vigilance and rapid response from security teams even more imperative.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Overall, this new threat highlights a perennial problem in cybersecurity: the gap between patch availability and actual implementation. The longer organizations delay updating their systems, the longer the window of opportunity for attackers increases, turning a known vulnerability into a real crisis.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS