FortiGuard Outbreak Alert: Citrix NetScaler Memory Overread Vulnerability
Description | NetScaler ADC is an application delivery and load balancing solution that improves the performance, availability, and security of enterprise applications. NetScaler Gateway is a secure remote access and VPN solution that enables users to securely access internal applications and virtual desktops from anywhere. CVE-2026-3055 is an out-of-bounds read vulnerability in NetScaler ADC and NetScaler Gateway configured as a SAML Identity Provider (IdP) which allows an unauthenticated remote attacker to trigger a memory over-read and disclose sensitive information stored in memory.
| ||||||||||||
CVE ID    | |||||||||||||
NDR Cloud Detection Rule | FortiNDR Cloud v26.2b+
| ||||||||||||
Playbook | N/A | ||||||||||||
Threat Hunting | FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for "Citrix NetScaler Memory Overread Vulnerability" related activities. | ||||||||||||
Suricata/DPI Coverage | Customers can create custom investigation/detections using the Suricata and DPI signatures below: DPI:
Suricata:
| ||||||||||||
Other Fortinet Products | For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to Citrix NetScaler Memory Overread Vulnerability. |
