CVE-2026-3055: Citrix NetScaler SAML IDP Memory Overread — Technical Analysis & Remediation

Technical root cause and active exploitation telemetry for the Citrix NetScaler SAML session memory overread flaw.

CVE-2026-3055: Citrix NetScaler SAML IDP Memory Overread — Technical Analysis & Remediation
📌
Security Roundup Series: Week of June 4, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-3055 Severity: CVSS 9.4 Status: ⚠️ Actively Exploited In The Wild Target Component: Citrix NetScaler ADC & Gateway SAML IDP

← Back to the June 4 Security Roundup

Overview

CVE-2026-3055 is an out-of-bounds memory read (CWE-125) in Citrix NetScaler ADC and NetScaler Gateway when configured as a SAML Identity Provider (SAML IDP). An unauthenticated attacker can send crafted HTTP requests to the /saml/login endpoint to leak memory from the previous request, potentially exposing session tokens, credentials, or cryptographic material. CVSS v3.1 base score: 9.3 (Critical). CISA added it to the KEV catalog on March 30, 2026; Fortinet confirmed large-scale active exploitation in May 2026.

Affected Versions

  • NetScaler ADC and Gateway < 14.1-43.12
  • NetScaler ADC and Gateway 13.1 < 13.1-57.10
  • NetScaler ADC and Gateway 13.0 (end of life – no patch; upgrade required)

Vulnerability Details

The vulnerability occurs in the SAML IDP handler within nsppe. When processing the /saml/login endpoint, the code checks for the presence of the wctx query parameter but does not validate that it contains a value (it may be present as a bare wctx key without an = sign). In this case, the handler attempts to access the associated buffer with an incorrect offset, causing an out-of-bounds read of residual memory from a previous HTTP request.

Attack Chain

  1. Enumerate SAML IDP: Probe for SAML IDP mode via GET /cgi/GetAuthMethods. Response includes "saml" in the auth methods array if the appliance is configured as a SAML IDP.
  2. Trigger memory leak: Send GET /saml/login?wctx HTTP/1.1 (note: wctx without = value). The NSC_TASS handler reads stale memory and echoes it in the response body.
  3. Extract sensitive data: Repeat requests to harvest different memory regions. Leaked data has been confirmed to include Base64-encoded session cookies, HTTP Authorization headers, and partial SAML assertions from prior requests.
  4. Session hijack or credential replay: Use extracted session tokens to authenticate to downstream services or replay stolen SAML assertions to impersonate users to the service provider.

PoC Request

GET /saml/login?wctx HTTP/1.1
Host: target-netscaler.example.com
User-Agent: Mozilla/5.0
Connection: close

# Response contains leaked memory after the HTML body.
# Look for Base64 blobs or Authorization header fragments.

IOCs

  • High volume of GET /saml/login?wctx requests (without =) in NetScaler access logs
  • Unusual authentication events in SAML service provider logs (logins from unexpected IP ranges)
  • Scanning activity probing /cgi/GetAuthMethods from the same source IPs

Remediation

# 1. Upgrade NetScaler ADC/Gateway:
#    - 14.1 → 14.1-43.12 or later
#    - 13.1 → 13.1-57.10 or later
#    - 13.0 → Upgrade to 13.1 or 14.1 (EOL, no patch)

# 2. If immediate upgrade is not possible, disable SAML IDP functionality:
#    In the Citrix ADC CLI:
set authentication samlIdPProfile -DISABLED

# 3. Apply a web application firewall (WAF) rule to block requests matching:
#    URI: /saml/login  Query: wctx without = sign
#    Citrix ADC AppFW signature rule (add to your policy):
#    RULE: MATCH_URI "/saml/login" AND QUERY_STRING "wctx" NOT CONTAINS "="
#    ACTION: BLOCK

# 4. Review logs for prior exploitation:
grep 'GET /saml/login?wctx ' /var/nslog/httprequest.log | awk '{print $1}' | sort | uniq -c | sort -rn

← Back to the June 4 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther