CitrixBleed 3: critical Citrix NetScaler flaw under active attack
A critical vulnerability in Citrix NetScaler appliances, nicknamed CitrixBleed 3 and tracked as CVE-2026-3055, lets unauthenticated attackers read leftover memory and steal session tokens, SAML assertions, and stored credentials. CISA has added it to its Known Exploited Vulnerabi
Security teams are racing to patch CitrixBleed 3, a critical flaw in Citrix NetScaler ADC and NetScaler Gateway tracked as CVE-2026-3055. NetScaler appliances sit at the network perimeter, handling remote access, load balancing, and single sign-on for thousands of organizations. The bug is a memory overread: when a NetScaler is set up as a SAML identity provider, an unauthenticated attacker sends malformed login requests and reads leftover chunks of the appliance's memory, which can contain active session tokens, SAML assertions, and stored credentials. That is enough to hijack a logged-in session or impersonate a user without ever knowing a password. CISA added the bug to its Known Exploited Vulnerabilities catalog just days after disclosure, and Fortinet $FTNT reports large-scale exploitation in the wild. The same class of NetScaler flaw powered the original CitrixBleed attacks that fed major ransomware campaigns, because a stolen session token sidesteps multifactor authentication entirely. Patching alone is not enough: teams also need to rotate credentials and hunt for sessions that were already stolen.