Skip to main content
kcheung
Staff
Staff
June 30, 2026

FortiGuard Outbreak Alert: Citrix NetScaler Memory Overread Vulnerability

  • June 30, 2026
  • 0 replies
  • 16 views

Description

NetScaler ADC is an application delivery and load balancing solution that improves the performance, availability, and security of enterprise applications.

NetScaler Gateway is a secure remote access and VPN solution that enables users to securely access internal applications and virtual desktops from anywhere.

CVE-2026-3055 is an out-of-bounds read vulnerability in NetScaler ADC and NetScaler Gateway configured as a SAML Identity Provider (IdP) which allows an unauthenticated remote attacker to trigger a memory over-read and disclose sensitive information stored in memory.


The following versions of NetScaler are vulnerable to CVE-2026-3055:

  • NetScaler ADC and NetScaler Gateway 14.1: Version < 14.1-60.58

  • NetScaler ADC and NetScaler Gateway 13.1: Version < 13.1-62.23

  • NetScaler ADC FIPS and NDcPP: Version < 13.1-37.262

CVE ID    

CVE-2026-3055

NDR Cloud Detection Rule

FortiNDR Cloud v26.2b+

Detection Rule Name

Category

Primary MITRE ID

FortiGuard Outbreak Alert: Citrix NetScaler Memory Out-of-Bounds Read - CVE-2026-3055

Attack: Exploitation

T1190 - Exploit Public-Facing Application

Playbook 

N/A

Threat Hunting

FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for "Citrix NetScaler Memory Overread Vulnerability" related activities.
IOC source: Citrix NetScaler Memory Overread Vulnerability | Indicators of Compromise.
All IOCs relating to "Citrix NetScaler Memory Overread Vulnerability" have been added to Threat Intelligence Intel.

Suricata/DPI Coverage

Customers can create custom investigation/detections using the Suricata and DPI signatures below:

DPI:

DPI Vulnerability ID (dpi_vuln_id)

DPI Alert Signature

60635

Citrix.NetScaler.CVE-2026-3055.Out-of-Bounds.Read

Suricata:

Suricata Signature ID

Suricata Signature

2068631

ET WEB_SPECIFIC_APPS Citrix Netscaler SAML IDP Memory Overread (CVE-2026-3055) M1

2068632

ET WEB_SPECIFIC_APPS Citrix Netscaler SAML IDP Memory Overread (CVE-2026-3055) M2

2068633

ET WEB_SPECIFIC_APPS Citrix Netscaler SAML IDP Memory Overread - NSC_TASS Cookie Response (CVE-2026-3055)

Other Fortinet Products

For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to Citrix NetScaler Memory Overread Vulnerability.