HIGHVulnerability
Verified
Global
CISA KEV: Citrix NetScaler — Citrix NetScaler Out-of-Bounds Read Vulnerability
Monday, March 30, 2026 at 12:00 AM UTC·Source: CISA KEV
Updated: Wednesday, April 1, 2026 at 07:13 PM UTC
Executive Summary
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Analysis
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Added to CISA Known Exploited Vulnerabilities catalog on 2026-03-30. Remediation due: 2026-04-02.