Citrix security advisory (AV26-267) – Update 1

Serial number: AV26-267
Date: March 23, 2026
Updated: March 30, 2026

On March 23, 2026, Citrix published a security advisory to address critical vulnerabilities in the following products:

  • NetScaler ADC and NetScaler Gateway 14.1 – versions prior to 14.1-60.58
  • NetScaler ADC and NetScaler Gateway 13.1 – versions prior to 13.1-62.23
  • NetScaler ADC FIPS and NDcPP – versions prior to 13.1-37.262

Update 1

On March 30, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-3055 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.

Date modified: