🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Citrix NetScaler Unauthenticated Remote Code Execution (CVE-2026-3055) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateApril 21, 2026
CVECVE-2026-3055
CVSS Score9.8
Affectednetscaler_application_delivery_controller, netscaler_gateway
📋Executive Summary
Attackers are actively exploiting CVE-2026-3055, a critical vulnerability in Citrix NetScaler appliances that allows remote code execution without authentication. The vulnerability affects NetScaler ADC and Gateway products, giving attackers complete control over these network edge devices. Researchers from watchTowr and Defused confirmed active exploitation in the wild.
⚠️Why It Matters for MSSPs
NetScaler appliances sit at the network perimeter for many MSSP clients, making this a direct path into client environments if exploited. Your own infrastructure likely depends on NetScaler for remote access and load balancing, creating a double exposure where one compromised appliance could expose your entire client portfolio.
Recommended Action
Immediately patch all NetScaler ADC and Gateway appliances to the latest firmware version and notify all clients running NetScaler infrastructure within 24 hours.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.