Vulnerabilities · 5h ago

Citrix NetScaler SAML flaw allows remote code execution

Citrix has patched CVE-2026-107406, a critical flaw in NetScaler ADC and NetScaler Gateway that can let a remote attacker run code or cause a denial of service. CSIRT Italia, NCSC-NL, and INCIBE-CERT said the bug matters only on systems where SAML is enabled, including NetScaler instances configured as a SAML identity provider or service provider.

The bug is a memory overflow in SAML processing: specially crafted identity traffic can make the appliance mishandle memory instead of just rejecting a login. That puts the authentication edge itself at risk, so hybrid Secure Private Access deployments that rely on those NetScaler instances inherit the same exposure.

For operators, the key point is scope, not just severity. This is a serious patch item, but the immediate blast radius is the SAML-enabled subset of ADC and Gateway appliances, not every NetScaler box in the estate.

CVE-2026-107406

NVD KEV

Timeline

Sources

6 sources covering this story

Entities

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-10-09

Editions

Related stories