Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | watchTowr Labs ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch. Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2025-5777, CVE-2026-3055. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055? While we've been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately identify exploitable Citrix NetScaler appliances across the watchTowr client base, we couldn't help but wonder: could there be more hiding in Citrix's patches?These thoughts, and worse, naturally come to us at 6 am on a Sunday morning.Welcome back to the hellscape, and yet another watchTowr Labs blog post.What we can confidently conclude, post-analysis, is that CVE-2026-3055 is not one singular memory overread vulnerability. In fact, this CVE ID has been assigned to at least two memory overread vulnerabilities, affecting the following endpoints:/saml/login/wsfed/passive?wctx Some would say this is disingenuous, Citrix.Unrelated, and without comment, we leave a screenshot of part of CISA's Secure By Design pledge, which of course Citrix are a signer of:The prerequisites for exploitation haven't changed, to quote from Part 1: Citrix advises that the vulnerability is only exploitable if the appliance is 'configured as a SAML IDP'. This is a cursed configuration to begin with, and we can think of no appliance more poorly-suited to the task of being an IdP than this class of network device.In-The-Wild ExploitationBefore we move on, we need to say something clearly: in-the-wild exploitation has begun, with evidence from our honeypot network showing exploitation from known threat actor source IPs as of March 27th.This is an …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- critical CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- high You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
- medium The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
- high You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)