CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out-of-Bounds Read
2026-03-24T07:23:54Z•f573c7c52e1396f8c03d9c9472a41e62c1fa52a65ac666ec52027bd2ee51ef19
CVE-2025-64328CVE-2026-29058CVE-2026-3055CVE-2026-31381CVE-2026-31382CitrixGainsightMetasploitNetScalerSAMLinformation disclosureout-of-bounds readpatchthreat landscapevulnerability
What happened
Rapid7 blog roundup highlights a critical Citrix NetScaler ADC/NetScaler Gateway vulnerability (CVE-2026-3055) — an unauthenticated out-of-bounds read (CVSS 9.3) that can leak memory from appliances configured as a SAML Identity Provider (default configs unaffected). The feed also notes Metasploit updates adding exploit modules (including coverage for CVE-2026-29058 and CVE-2025-64328) and Rapid7-discovered Gainsight Assist flaws: an information disclosure (CVE-2026-31381) and a reflected XSS (CVE-2026-31382) that have been patched. Additional posts cover threat trends, CNAPP product updates,和
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- f573c7c52e1396f8c03d9c9472a41e62c1fa52a65ac666ec52027bd2ee51ef19
- Enrichment time
- 2026-03-24T07:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.