Critical Citrix NetScaler memory flaw actively exploited in attacks

2026-03-30T19:23:40Z72ceb6ae0e612f3e5ffeeef10313f7c5c56fc03c3185af4a48767d2e1b44dcdf
CVE-2026-3055Citrix NetScalerEuropa.eu breachF5 BIG-IPFBI email compromiseFortinet FortiClient EMSHandalaInfinity StealerPyPIRCEShinyHuntersTelnyxWindows updateWordPress Smart Slideractive-exploitationcriticalmacOS ClickFixmalwarememory-flawpatchingsupply-chainwebshell

What happened

Multiple actively exploited, high-risk vulnerabilities and supply-chain attacks reported. Notable items: a critical memory flaw in Citrix NetScaler ADC/Gateway (CVE-2026-3055) is being exploited to access sensitive data; an F5 BIG‑IP APM bug has been reclassified to critical RCE and is being used to deploy webshells; and a critical Fortinet FortiClient EMS vulnerability is also under active exploitation. Other incidents include a Europa.eu data breach (ShinyHunters), compromise of FBI Director Kash Patel’s personal email (Handala), a backdoored Telnyx PyPI package delivering credential-stealer

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
72ceb6ae0e612f3e5ffeeef10313f7c5c56fc03c3185af4a48767d2e1b44dcdf
Enrichment time
2026-03-30T19:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.