Vulnerabilities & Exploits

Citrix NetScaler SAML flaw allows remote code execution

Citrix has patched CVE-2026-107406, a critical flaw in NetScaler ADC and NetScaler Gateway that can let a remote attacker run code or cause a denial of service. CSIRT Italia, NCSC-NL, and INCIBE-CERT said the bug matters only on systems where SAML is enabled, including NetScaler instances configured as a SAML identity provider or service provider.

The bug is a memory overflow in SAML processing: specially crafted identity traffic can make the appliance mishandle memory instead of just rejecting a login. That puts the authentication edge itself at risk, so hybrid Secure Private Access deployments that rely on those NetScaler instances inherit the same exposure.

For operators, the key point is scope, not just severity. This is a serious patch item, but the immediate blast radius is the SAML-enabled subset of ADC and Gateway appliances, not every NetScaler box in the estate.

6 sources · 6h ago

CVE-2026-107406

NVD KEV

Timeline

Sources

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-10-09

Every edition of this story: Citrix NetScaler SAML flaw allows remote code execution

More from today