Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-107406

Memory overflow in Citrix NetScaler ADC and Gateway SAML handling

Memory overflow in Citrix NetScaler ADC and Gateway SAML SP/IdP handling allows unauthenticated RCE or denial of service. CVSS 9.5 critical. Patches available.

Vendor
Citrix
Product
NetScaler ADC, NetScaler Gateway
CVSS
9.5
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-107406 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway affecting deployments configured as a SAML Service Provider (SP), SAML Identity Provider (IdP), or in Secure Private Access Hybrid mode.

An unauthenticated remote attacker can exploit the flaw to achieve remote code execution or trigger a denial-of-service condition. Citrix rates the severity as critical at CVSS 9.5.

Citrix released patched builds across the 14.1, 13.1, and FIPS branches. Full version details and upgrade targets are in the CTX697191 security bulletin. As of advisory publication, Citrix reported no confirmed in-the-wild exploitation, though three prior critical NetScaler advisories from the same period (CVE-2026-88779, CVE-2026-88772, CVE-2026-88771) were added to the CISA KEV catalog shortly after initial disclosure.

Mitigation: Upgrade to the patched build specified in CTX697191 for your branch. If immediate patching is not possible, review the advisory for any available workarounds and prioritize restricting external access to SAML endpoints.