Skip to content
Citrix NetScaler Memory Overread Vulnerability

Citrix NetScaler Memory Overread Vulnerability

Filestore.Fortinet May 28, 2026

Telemetry collected over the past 30 days shows sustained exploitation activity, with FortiGuard IPS sensors frequently detecting over 2,000 blocked CVE-2026-3055 attack attempts per day and peaks exceeding 2,700 daily events. The activity primarily targets exposed NetScaler SAML services across the Technology, Telecom, Automotive, MSSP, and Government sectors, with the highest concentration of attacks observed in Germany, Hong Kong, France, the United States, and Poland. The vulnerability exists due to insufficient validation of user-supplied parameters during SAML authentication processing. Crafted requests sent to vulnerable SAML endpoints can trigger memory overread conditions, causing portions of process memory to be returned to the attacker. The vulnerability has received a CVSS v4 score of 9.3 (Critical) and has been added to the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities (KEV) catalog following confirmed in-the-wild exploitation activity. Most observed activity involves opportunistic scanning and automated exploitation attempts originating from rapidly changing infrastructure, including VPS providers, botnets, and anonymized networks.

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.

Organizations that have not remediated affected systems remain at risk of credential exposure, account compromise, and unauthorized access to internal resources.The continued volume of observed attacks highlights the elevated risk posed by unpatched or internet-exposed systems, particularly where NetScaler appliances provide federated authentication or remote access services.

May 25, 2026: CVE-2026-3055 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

March 03, 2026: Public disclosure and security advisories released for CVE-2026-3055, warning of unauthenticated memory disclosure risks affecting NetScaler ADC and Gateway appliances.

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.

Assisted Response Services

Attack Surface Hardening

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.

Sources of information in support and relation to this Outbreak and vendor.