Urgent Alert: NetScaler bug CVE-2026-3055 probed by attackers could leak sensitive data

2026-03-29T14:51:48Z9d35e8ab923bcc65e0bed3cfc743ee0f1d7e579d000bf24de56895275b70cc6f
AITM phishingApple iOS lock‑screen alertsBSICISACVE-2025-53521CVE-2026-3055CVE-2026-4681Citrix NetScalerF5 BIG-IPFlexPLMHandalaKnown Exploited Vulnerabilities (KEV)PTC WindchillShinyHuntersTikTok Businessactive probescritical vulnerabilitymalwarememory overreadsupply chain compromise

What happened

This feed reports multiple high‑severity active threats and disclosures: attackers are actively probing a critical Citrix NetScaler ADC/Gateway memory overread vulnerability (CVE-2026-3055, CVSS 9.3) that can leak sensitive data; CISA added an F5 BIG‑IP AMP flaw (CVE-2025-53521, CVSS 9.8) to its Known Exploited Vulnerabilities catalog; and CISA/BSI warned of an unpatched, critical PTC Windchill/FlexPLM flaw (CVE-2026-4681, CVSS 10.0) with potential imminent exploitation. Additional notable items include Apple sending lock‑screen warnings for active web‑based exploits on unpatched iPhones/iPads

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9d35e8ab923bcc65e0bed3cfc743ee0f1d7e579d000bf24de56895275b70cc6f
Enrichment time
2026-03-29T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.