Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug

2026-03-28T13:24:06Z20fd708bf3acf16c28489fe172ea264a5df97cf7639ce62b1a1a490127694116
CVE-2025-53521CVE-2026-3055PyPITeamPCPapplebearlyfybig-ipcitrixclaude-extensioncorunadarksworddevice-code-phishingf5ios-exploitslangchainlanggraphlitellmnetscalerransomwaresupply-chaintelnyxwebrtc-skimmer

What happened

Multiple high‑severity and active threats reported: Citrix NetScaler ADC/Gateway is under active reconnaissance for CVE-2026-3055 (insufficient input validation → memory overread, CVSS 9.3). CISA added CVE-2025-53521 (F5 BIG-IP APM, RCE, CVSS 9.3) to its KEV list after observed exploitation. Supply‑chain compromises by TeamPCP pushed malicious PyPI and backdoored litellm/telnyx package versions that steal credentials and provide persistence. Additional high‑impact activity includes iOS exploit kits (DarkSword, Coruna), Apple warnings for web‑based iOS exploits, zero‑click XSS in the Claude Ch‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
20fd708bf3acf16c28489fe172ea264a5df97cf7639ce62b1a1a490127694116
Enrichment time
2026-03-28T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug · Baitaphish