CVE-2026-3055: Citrix NetScaler ADC and NetScaler Gateway Out-of-Bounds Read

2026-03-24T07:23:54Zf573c7c52e1396f8c03d9c9472a41e62c1fa52a65ac666ec52027bd2ee51ef19
CVE-2025-64328CVE-2026-29058CVE-2026-3055CVE-2026-31381CVE-2026-31382CitrixGainsightMetasploitNetScalerSAMLinformation disclosureout-of-bounds readpatchthreat landscapevulnerability

What happened

Rapid7 blog roundup highlights a critical Citrix NetScaler ADC/NetScaler Gateway vulnerability (CVE-2026-3055) — an unauthenticated out-of-bounds read (CVSS 9.3) that can leak memory from appliances configured as a SAML Identity Provider (default configs unaffected). The feed also notes Metasploit updates adding exploit modules (including coverage for CVE-2026-29058 and CVE-2025-64328) and Rapid7-discovered Gainsight Assist flaws: an information disclosure (CVE-2026-31381) and a reflected XSS (CVE-2026-31382) that have been patched. Additional posts cover threat trends, CNAPP product updates,和

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
f573c7c52e1396f8c03d9c9472a41e62c1fa52a65ac666ec52027bd2ee51ef19
Enrichment time
2026-03-24T07:23:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.