NEWS 10/10 and 2700 attacks per day. Recorded a large-scale wave of exploitation of the vulnerability in Citrix NetScaler

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,662
How the vulnerability works in Citrix, which allows you to read the contents of someone else’s memory without a single password.
1780481514234.png
Citrix NetScaler is again massively attacked through critical vulnerability. Experts record thousands of attacks every day, and the vulnerability has already been included in the list of actively operated CISA.

According to FortiGuard Labs, the attackers continue to search for vulnerable Citrix NetScaler ADC and NetScaler Gateway systems available from the Internet. Attacks are primarily aimed at a configuration where devices are used as a provider of SAML certificates for corporate authentication.

The problem CVE-2026-3055 (CVSS:4.0/AV:N/AV:N/N/N/IN/VC:H/VC:H/VC/VC:H/VC:H/SC/SC:L:L/SIL/SAL:L:L:L:L:C:C](Critical)) is related to memory reading error. When the device processes SAML queries, it does not check some custom parameters. A specially formed request is able to force the system to return parts of the contents of memory to the attacker. As a result, authentication tokens, session data and other sensitive information are at risk.

FortiGuard’s telemetry shows that over the past 30 days, the number of attacks has remained stably high. The company’s detection tools regularly blocked more than 2000 attempts to operate CVE-2026-3055 per day. On certain days, the number of incidents exceeded 2700.

The most active attackers attack organizations from the technological sector, the telecommunications industry, the automotive industry, as well as government structures and suppliers of managed security services. Most of the attempts of attacks were recorded in Germany, Hong Kong, France, the United States and Poland. When the real attacks were confirmed, CISA included CVE-2026-3055 in the Keyno Exploited Vulnerabilities catalog, which contains information about vulnerabilities already used by attackers in practice.

Most of the recorded attacks are massive. The attackers act with rapidly changing infrastructure, including virtual servers, botnets, and anonymized networks. Such activity allows them to constantly scan the Internet in search of unprotected devices.

FortiGuard warns that organizations that have not established corrections risk encountering account leakage, compromising corporate accounts and unauthorized access to internal resources. Particularly high risk is maintained for the systems through which employees receive remote access to corporate services. Public information about CVE-2026-3055 appeared on March 3, 2026. On May 25, the vulnerability was added to the catalog of actively exploited CISA problems, which confirmed its high attractiveness for attackers.
 
6,412Threads
86,526Messages
6,082Members
Zero OneLatest member
Top Bottom