CVE-2026-107406
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: For the following versions: Applicable only when configured as a SAML IdP: NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: NetScaler ADC and NetScaler Gateway before 14.1-73.37 NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS NetScaler ADC and NetScaler Gateway before 13.1-64.23 NetScale
1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026
Coverage timeline
-
Citrix Urges NetScaler Users to Patch Critical Flaw Enabling Remote Code Executionsecurityonline.info · Oct 9, 2026