Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
2026-03-28T13:24:06Z•20fd708bf3acf16c28489fe172ea264a5df97cf7639ce62b1a1a490127694116
CVE-2025-53521CVE-2026-3055PyPITeamPCPapplebearlyfybig-ipcitrixclaude-extensioncorunadarksworddevice-code-phishingf5ios-exploitslangchainlanggraphlitellmnetscalerransomwaresupply-chaintelnyxwebrtc-skimmer
What happened
Multiple high‑severity and active threats reported: Citrix NetScaler ADC/Gateway is under active reconnaissance for CVE-2026-3055 (insufficient input validation → memory overread, CVSS 9.3). CISA added CVE-2025-53521 (F5 BIG-IP APM, RCE, CVSS 9.3) to its KEV list after observed exploitation. Supply‑chain compromises by TeamPCP pushed malicious PyPI and backdoored litellm/telnyx package versions that steal credentials and provide persistence. Additional high‑impact activity includes iOS exploit kits (DarkSword, Coruna), Apple warnings for web‑based iOS exploits, zero‑click XSS in the Claude Ch‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 20fd708bf3acf16c28489fe172ea264a5df97cf7639ce62b1a1a490127694116
- Enrichment time
- 2026-03-28T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.