Post #3585369
2026-06-03 18:21 UTC
PSA for anyone still running NetScaler as a SAML IdP
CVE-2026-3055 (memory overread, CVSS 9.3) is on CISA KEV and getting hammered in the wild. Leaks session tokens and creds straight out of process memory. It's also a CVE Interlock is associated with, and they love healthcare.
Patch the appliance, but if you've got a FortiGate in front of it, drop an IPS profile on and virtual-patch it today. Signature's live.
Alert: https://www.fortiguard.com/outbreak-alert/citrix-netscaler-memory-overread
Interlock: https://www.fortiguard.com/threat-actor/6384
#infosec #CVE #NetScaler #ransomware
Replies (0)
No replies.