securityonline.info 9 Oct 2026, 01:37 UTC

Citrix Urges NetScaler Users to Patch Critical Flaw Enabling Remote Code Execution

Citrix Urges NetScaler Users to Patch Critical Flaw Enabling Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CITRIX has flagged a critical memory overflow flaw in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406, with a CVSS v4 score of 9.5. The vulnerability may lead to remote code execution or denial of service when NetScaler appliances are configured to act as a SAML service provider (SP) or identity provider (IdP). Citrix notes there are no confirmed exploits at the time of the advisory, but urges immediate remediation.

The issue affects specific builds depending on the SAML role: SAML IdP only is vulnerable in 14.1-73.37 to 14.1-73.41 and 13.1-64.23 to 13.1-64.28 (including corresponding FIPS/NDcPP builds); both SP and IdP roles are affected in older releases prior to 14.1-73.37 and 13.1-64.23 (plus matching FIPS/NDcPP builds). Appliances with no SAML configuration are not affected, and Citrix-managed cloud services are not impacted.

The recommended mitigation is to upgrade to fixed releases: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283 FIPS (as applicable). Administrators should first verify whether their NetScaler configuration contains the signs “add authentication samlAction” (SP) or “add authentication samlIdPProfile” (IdP); if present on an affected build, apply the listed fixes. Citrix emphasises the urgency of updating, given NetScaler’s edge-network role and the potential for rapid exploitation in targeted campaigns. Date references are 9 October 2026.

View full article

Article by CyberSIXT