Citrix has patched CVE-2026-107406, a critical flaw in NetScaler ADC and NetScaler Gateway that can let a remote attacker run code or cause a denial of service. CSIRT Italia, NCSC-NL, and INCIBE-CERT said the bug matters only on systems where SAML is enabled, including NetScaler instances configured as a SAML identity provider or service provider.
The bug is a memory overflow in SAML processing: specially crafted identity traffic can make the appliance mishandle memory instead of just rejecting a login. That puts the authentication edge itself at risk, so hybrid Secure Private Access deployments that rely on those NetScaler instances inherit the same exposure.
For operators, the key point is scope, not just severity. This is a serious patch item, but the immediate blast radius is the SAML-enabled subset of ADC and Gateway appliances, not every NetScaler box in the estate.
Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.