CITRIX has released security updates for CVE-2026-107406, a critical memory overflow flaw affecting NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial-of-service under certain configurations. The vulnerability is triggered when the appliance is configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP).
Citrix notes the impact depends on the specific system setup and stresses that affected deployments could allow attackers to run arbitrary code remotely or disrupt services if the preconditions are met. The company reports a CVSS v4.0 base score of 9.5 and states there are no known unmitigated exploits at the time of the bulletin.
The advisory lists affected software versions and the fixed releases: NetScaler ADC and NetScaler Gateway 14.1-73.46 and later; 13.1-64.29 and later (13.1); 14.1-FIPS 14.1-73.46 FIPS and later; 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later. Organisations should verify their NetScaler configurations to determine whether their appliance is acting as an SP or IdP by checking for specific entries like add authentication samlAction (SP) or add authentication samlIdPProfile (IdP).
Citrix references prior disclosures of other NetScaler flaws exploited in the wild and notes that the US CISA later added related CVEs to its Known Exploited Vulnerabilities catalog. As ever, patched deployments are recommended as soon as possible; Citrix advises affected customers to upgrade to the stated versions.