NetScaler ADC/Gateway patch memory overread flaws
Citrix patched two NetScaler ADC/Gateway vulnerabilities that could allow memory overread of sensitive data, including credentials, with no known active exploitation.
MS-ISAC issued an advisory detailing two vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that could allow an attacker to overread appliance memory, potentially exposing sensitive credentials. The more severe issue, CVE-2026-3055, is an out-of-bounds read caused by insufficient input validation, requiring the appliance to be configured as a SAML Identity Provider. A second flaw, CVE-2026-4368, is a race condition affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server.
Successful exploitation of CVE-2026-3055 could expose highly sensitive credentials stored in appliance memory, which could subsequently be leveraged to achieve remote code execution. Affected versions include NetScaler ADC and Gateway 14.1 prior to 14.1-66.59, 13.1 prior to 13.1-62.23, and 13.1-FIPS/13.1-NDcPP prior to 13.1-37.262. As of publication, there are no reports of these vulnerabilities being exploited in the wild.
CISA/MS-ISAC recommend organizations apply Citrix's updates immediately after testing, alongside standard hardening measures such as vulnerability management, network segmentation, least-privilege enforcement, and exploit protection controls. Given the widespread enterprise use of NetScaler for remote access and application delivery, unpatched systems remain an attractive target for future exploitation despite the current lack of observed attacks.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-netscaler-adc-and-netscaler-gateway-could-allow-for-memory-overread_2026-025
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free