Back to Newsroom
Threat Intel

Citrix Patches Critical NetScaler Flaw Opening Door to Remote Code Execution

A maximum-severity memory overflow bug in NetScaler ADC and Gateway can be triggered through SAML authentication, letting an attacker run code remotely or crash the appliance.

Citrix Patches Critical NetScaler Flaw Opening Door to Remote Code Execution

Citrix has shipped fixes for a critical vulnerability in NetScaler ADC and NetScaler Gateway that could let an attacker execute code remotely or crash the appliance when it is configured as a SAML identity provider or service provider.

Tracked as CVE-2026-107406, the flaw is a memory overflow issue carrying a maximum-severity CVSS score of 9.5 out of 10. Citrix says it has no evidence of in-the-wild exploitation so far. The issue was reported through coordinated disclosure by a team of researchers at a major financial institution's internal security unit, along with an independent researcher.

What happened

The bug only bites NetScaler instances where SAML authentication is active - either as an identity provider (IdP) or a service provider (SP). Administrators can check their own configuration for add authentication samlAction or add authentication samlIdPProfile entries to see whether they're exposed. Secure Private Access Hybrid deployments that rely on NetScaler fall within the affected scope too.

Impacted version ranges span both the 14.1 and 13.1 release branches, including the FIPS and NDcPP-certified builds, so teams should match their exact build number against Citrix's advisory rather than assume a whole release line is safe or unsafe.

Why it matters

A 9.5 CVSS score on an internet-facing authentication component is about as serious as it gets. NetScaler appliances sit at the perimeter of a huge number of corporate networks and have repeatedly become a favorite target for ransomware crews once a working exploit circulates. Citrix's advisory also lands in the same window as three unrelated NetScaler flaws that are already being actively exploited - a reminder that attackers move fast on this product line once any CVE details go public, whether or not that specific bug has a public exploit yet.

What to do

  • Patch now. Upgrade to NetScaler ADC/Gateway 14.1-73.46 or later, 13.1-64.29 or later, 14.1-FIPS 14.1-73.46 or later, or 13.1-FIPS/13.1-NDcPP 13.1-37.283 or later.
  • Check your SAML configuration before assuming you're out of scope - this flaw specifically targets SAML IdP/SP setups, not every NetScaler deployment.
  • Review for the other actively-exploited NetScaler CVEs disclosed around the same time, since appliances are often chained once an attacker has any foothold.
  • Prioritize internet-facing identity and access gateways in your patch cycle, and confirm patch status through your own asset inventory rather than relying on the vendor bulletin alone.
SHARE