Release notes for update package 2003-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Tuesday March 31, 2026
MD5 CHECKSUM:     ec422a7760a9c241dace9396723810b1
SHA1 CHECKSUM:     e5a77270e1b098829a0fbc18eaf51a4610a6c0d5
SHA256 CHECKSUM:     bd9f367717fafcc4565c1260313e22ef4c1bc21367488b96dd7c761a00c7b577


UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in NetScaler ADC and NetScaler Gateway     CVE-2026-3055     Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055
High     An attempt to exploit a vulnerability in NetScaler ADC and NetScaler Gateway     CVE-2026-3055     Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055
Low     An attempt to exploit a vulnerability in NetScaler ADC and NetScaler Gateway     CVE-2026-3055     Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055

Jump to: Detected Attacks Other Changes

DETECTED ATTACKS

New detected attacks:

HTTP Request URI

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 CVE-2026-3055 HTTP_CSU-Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 Suspected Compromise

HTTP Reply Header Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 CVE-2026-3055 HTTP_SHS-Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 Suspected Compromise

HTTP Normalized Request-Line

Risk Vulnerability/Situation References Related Fingerprint Situation Type
Low Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 CVE-2026-3055 HTTP_CRL-Citrix-NetScaler-Saml-IDP-Memory-Overread-CVE-2026-3055 System Inspections

LIST OF OTHER CHANGES:

Updated objects:

Type Name Changes
IPList TOR exit nodes IP Address List
IPList Amazon AMAZON
IPList TOR relay nodes IP Address List
IPList Microsoft Office 365 Common and Office Online
IPList Okta IP Address List
IPList Botnet IP Address List
IPList Malicious Site IP Address List
IPList NordVPN Servers IP Address List
IPList Amazon AMAZON sa-east-1
IPList Amazon AMAZON us-east-1
IPList Amazon EC2 us-east-1
IPList Amazon AMAZON us-east-2
IPList Amazon EC2 us-east-2
IPList Forcepoint Drop IP Address List
IPList Microsoft Teams U.S. DoD endpoints
IPList Amazon AMAZON ap-southeast-3
Situation HTTP_CRL-Shared-Variables
Application Microsoft-Office-365
Application TOR
Application NordVPN

DISCLAIMER AND COPYRIGHT

Copyright © 2026 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.