Science & Tech · Cybersecurity · 2 days ago
Citrix patches critical NetScaler flaw affecting some SAML deployments
Citrix has released security updates for a critical flaw in its NetScaler ADC and NetScaler Gateway products.
The memory-overflow flaw could let an attacker run code remotely or disrupt services under certain conditions.
It affects deployments configured as a SAML identity provider or service provider, which customers can check in their device settings.
Citrix rates the vulnerability 9.5 out of 10 for severity.
Citrix says it is not aware of attacks exploiting this particular flaw.
The company recommends that affected customers upgrade to the patched versions, including NetScaler 14.1-73.46 or later and 13.1-64.29 or later, with separate updates for FIPS versions.
Some versions and configurations differ in which systems are affected, so customers should check Citrix’s advisory before upgrading.
Citrix released security updates for a critical memory overflow flaw in NetScaler ADC and NetScaler Gateway.
The flaw, CVE-2026-107406, could allow remote code execution or denial-of-service under specific configuration conditions.
The vulnerability affects deployments configured as a SAML identity provider or service provider.
Citrix said it was not aware of attacks exploiting the flaw in the wild.
Citrix recommends customers upgrade affected instances to patched versions.
- Who
- Citrix released the updates. The flaw was reported by Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov.
- What
- Citrix patched CVE-2026-107406, a critical memory overflow vulnerability that could enable remote code execution or denial-of-service.
- When
- Citrix announced the updates by October 9, 2026.
- Where
- NetScaler ADC and NetScaler Gateway deployments; the flaw also affects Secure Private Access Hybrid deployments using NetScaler instances.
- Why
- The flaw can enable remote code execution or disrupt services under specific conditions, particularly in systems configured as a SAML identity provider or service provider.
This story does not have two clearly opposing sides.
CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions.
We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
This story does not have a timeline yet.
- CVE
- CVE-2026-107406
- Severity
- CVSS score of 9.5; rated Critical
- Patched versions
- NetScaler ADC and Gateway 14.1-73.46 and later, and 13.1-64.29 and later
- SAML configuration
- Vulnerable deployments must be configured as a SAML service provider or identity provider
- Exploitation status
- Citrix said it was not aware of attacks exploiting this vulnerability in the wild











