Attackers are exploiting CVE-2026-3055, a CVSS 9.3 memory-overread vulnerability affecting Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers. Citrix disclosed the flaw on March 23, 2026; Defused Cyber and CrowdSec reported exploitation traces beginning March 27, with Defused Cyber observing widespread exploitation by March 29 and CrowdSec reporting more than 40 probing IP addresses over that weekend. Honeypot telemetry showed earlier attempts against older CitrixBleed vulnerabilities, followed by authentication-method enumeration and probing of federated-authentication endpoints.
Crafted SAML requests missing the AssertionConsumerServiceURL attribute reportedly disclose adjacent heap memory through the NSC_TASS response cookie, potentially exposing session material. WatchTowr identified disclosure through /saml/login and a more reliable leak through /wsfed/passive?wctx, with testing exposing active administrative session data. Organizations running affected configurations should immediately install the fixed releases specified in Citrix bulletin CTX696300. Where patching is delayed, restrict external access to relevant SAML, authentication, and management endpoints, and review logs for reconnaissance and exploitation indicators.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
By March 29, Defused Cyber observed widespread exploitation using crafted SAMLRequest payloads sent to /saml/login, with most retaining values from watchTowr's proof of concept. CrowdSec also reported more than 40 probing IP addresses over the weekend, predominantly hosted on Amazon infrastructure associated with AS16509.
Defused Cyber and CrowdSec reported initial CVE-2026-3055 exploitation activity beginning March 27, four days after Citrix's disclosure. Defused Cyber's timestamped examples in that section show reconnaissance requests rather than exploit payloads.
At 12:28 UTC on March 27, 38.54.88.49 requested /wsfed/passive?test&wctx on a NetScaler decoy. The report interprets the request as testing federated-authentication endpoint availability and context-parameter processing before exploit delivery.
At 00:19 UTC on March 27, 45.77.108.53 sent a POST request to /cgi/GetAuthMethods on a NetScaler honeypot. The report identifies this activity as reconnaissance to find appliances configured as SAML identity providers.
Citrix published bulletin CTX696300, disclosing CVE-2026-3055 and the lower-severity CVE-2026-4368 with patching guidance. CVE-2026-3055 is an unauthenticated memory-overread vulnerability rated CVSS 9.3 that affects NetScaler ADC and Gateway appliances configured as SAML identity providers.
On March 16, honeypots recorded more than 500 exploit attempts targeting CVE-2025-5777 and CVE-2023-4966 within 24 hours across multiple regions. The activity exceeded baseline levels, but the report did not establish a connection to advance knowledge of CVE-2026-3055.
Follow-up research identified /wsfed/passive?wctx as a second memory-disclosure path, triggered by supplying the wctx parameter without a value. watchTowr found that this path leaked substantially more data more reliably than the SAML variant, including active administrative session data during testing.
watchTowr's initial research identified memory disclosure through /saml/login, and a public proof of concept was subsequently reflected in observed attack payloads. Malformed SAML requests omitting AssertionConsumerServiceURL reportedly cause adjacent heap contents to appear in the NSC_TASS response cookie.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
defusedcyber.com
Open sourcecrowdsec.net
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.