NetScaler ADC, Gateway memory overread flaws disclosed
Two vulnerabilities in NetScaler ADC and Gateway could allow memory overread of sensitive data including credentials, potentially enabling remote code execution.
Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway that could allow attackers to perform memory overread operations on affected appliances. The most severe vulnerability, CVE-2026-3055, is an out-of-bounds memory read resulting from insufficient input validation that requires the appliance to be configured as a SAML Identity Provider. Successful exploitation could allow attackers to access highly sensitive credentials from appliance memory and potentially achieve remote code execution. A second vulnerability, CVE-2026-4368, involves a race condition affecting appliances configured as a Gateway or AAA virtual server.
Affected versions include NetScaler ADC and Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.262. There are currently no reports of these vulnerabilities being exploited in the wild. Organizations running affected versions should apply Citrix's security updates immediately after testing, particularly for internet-facing instances configured with the vulnerable features.
The MS-ISAC advisory recommends implementing comprehensive vulnerability management processes, automated patch management, network segmentation to isolate critical systems, and regular penetration testing. Organizations should prioritize remediation for externally-exposed NetScaler instances, especially those configured as SAML IDPs or Gateway services.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-memory-overread_2026-025
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free