Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread
CWE-125 class error (out-of-bounds read) results from insufficient input data validation in the SAML Identity Provider (IDP) handling component. An unauthorized attacker can send a crafted network request that causes data to be read outside the allocated memory buffer. The attack vector is network-based, requires no authentication or user interaction, significantly lowering the barrier to entry for attackers.
Attackers can gain unauthorized access to sensitive data stored in process memory (including credentials, session tokens, cryptographic keys), and depending on implementation — potentially cause device destabilization. The vulnerability threatens system confidentiality, integrity, and operational continuity.
Patches available from the vendor should be applied immediately according to Citrix technical support article CTX696300. Due to active exploitation in production environments and listing in CISA KEV catalog, the update should be deployed as a priority. Until patching, it is recommended to restrict network access to SAML IDP interfaces and monitor logs for anomalous requests.
Citrix NetScaler ADC and Citrix NetScaler Gateway configured in SAML Identity Provider (IDP) role — versions indicated in vendor references (article CTX696300).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCitrix Netscaler Application Delivery Controller
APPCitrix13.1 – 13.1-37.262 (excl.)13.1 – 13.1-62.23 (excl.)14.1 – 14.1-60.58 (excl.)Citrix Netscaler Gateway
APPCitrix13.1 – 13.1-62.23 (excl.)14.1 – 14.1-60.58 (excl.)
CISA KEV — detailsi
- Vendori
- Citrix ↗
- Producti
- NetScaler
- Added to KEVi
- March 30, 2026
- Remediation deadline (US Federal)i
- April 2, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
Related vulnerabilities
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway — RCE/DoS
Przepełnienie pamięci w Citrix NetScaler ADC i Gateway – RCE/DoS przez VPN
CitrixBleed 2 — memory overread w Citrix NetScaler ADC i Gateway
Citrix Bleed – wyciek tokenów sesji w NetScaler ADC i Gateway
Nieuwierzytelniony RCE w Citrix NetScaler ADC i Gateway