CITRIX has released patches for a critical vulnerability in NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service under certain configurations. The flaw, tracked as CVE-2026-107406, is described by Citrix as a memory overflow issue that could be triggered in deployments configured to use SAML either as an identity provider (IdP) or as a service provider (SP). The CVSS score is 9.5 out of 10, and Citrix notes there is no evidence of active exploitation in the wild.
The advisory specifies affected versions and configurations. When configured as a SAML IdP, NetScaler ADC and NetScaler Gateway versions 14.1-73.37 to 14.1-73.41 (inclusive), 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS (inclusive), and 13.1-64.23 to 13.1-64.28 (inclusive), plus 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1-37.282 (inclusive) are affected. When configured as a SAML SP or IdP, versions prior to 14.1-73.37 (and analogous pre-branch FIPS/NcDP entries) are affected.
Citrix warns that Secure Private Access Hybrid deployments are also at risk and urges customers to upgrade to the recommended versions. The vendor provides a list of fixed releases: 14.1-73.46 and later for 14.1-branch, 13.1-64.29 and later for 13.1-64 branch, and corresponding updates for FIPS and 13.1-NDcPP. The story notes that three related NetScaler flaws have seen active exploitation in the wild, underscoring the urgency of applying fixes.