Full Report
A vulnerability has been discovered in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway that could allow for remote code execution. Citrix NetScaler ADC (Application Delivery Controller) is an enterprise networking platform and traffic management device designed to optimize, secure, and accelerate the delivery of web and cloud applications. Successful exploitation of the most severe of these vulnerabilities could allow attackers to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes. To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP).
Analysis Summary
# Vulnerability: Citrix NetScaler ADC and Gateway Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-107406
- **CVSS Score:** Not explicitly listed in the source, but categorized as **High** risk by MS-ISAC.
- **CWE:** CWE-120 (Buffer Copy without Checking Size of Input / Memory Overflow)
## Affected Systems
- **Products:** Citrix NetScaler ADC and Citrix NetScaler Gateway.
- **Versions & Configurations:**
* **Configured as SAML IdP (Identity Provider) ONLY:**
* NetScaler ADC/Gateway: 14.1-73.37 to 14.1-73.41
* NetScaler ADC 14.1-FIPS: 14.1-73.37 FIPS to 14.1-73.41 FIPS
* NetScaler ADC/Gateway: 13.1-64.23 to 13.1-64.28
* NetScaler ADC 13.1-FIPS: 13.1-NDcPP 13.1-37.279 to 13.1-37.282
* **Configured as SAML SP (Service Provider) OR SAML IdP:**
* NetScaler ADC/Gateway: versions before 14.1-73.37
* NetScaler ADC 14.1-FIPS: versions before 14.1-73.37 FIPS
* NetScaler ADC/Gateway: versions before 13.1-64.23
* NetScaler ADC 13.1-FIPS: versions before 13.1-NDcPP 13.1-37.279
## Vulnerability Description
A memory overflow vulnerability exists in the SAML processing logic of Citrix NetScaler devices. If the appliance is configured to handle SAML authentication (acting as either an Identity Provider or Service Provider), an attacker can exploit this flaw to trigger a buffer overflow. This leads to either a Denial of Service (DoS) through system crashes or Remote Code Execution (RCE) with the privileges of the affected process.
## Exploitation
- **Status:** Not currently reported as exploited in the wild.
- **Complexity:** Low to Medium (Exploits public-facing applications).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for full system access).
- **Integrity:** High (Ability to execute arbitrary code).
- **Availability:** High (Can trigger crashes/DoS).
## Remediation
### Patches
Citrix has released updated versions to address this flaw. Administrators should upgrade to:
- NetScaler ADC and NetScaler Gateway **14.1-73.42** or later.
- NetScaler ADC and NetScaler Gateway **13.1-64.29** or later.
- *Note: Check specific FIPS-compliant releases if utilizing FIPS hardware.*
### Workarounds
No specific configuration workarounds were provided in the advisory; however, disabling SAML functionality (if not critical) would mitigate the attack surface until patches are applied.
## Detection
- **Indicators of Compromise:** Look for unusual crashes in the `nspipe` or `auth` processes. Monitor for unexpected network connections originating from the NetScaler management IP or VIPs.
- **Detection methods:** Perform authenticated penetration testing and vulnerability scanning (Safeguards 16.13 and 7.7) to verify if the SAML endpoint is susceptible to memory corruption payloads.
## References
- Citrix Advisory: `https[:]//support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191`
- CVE Record: `https[:]//www.cve.org/CVERecord?id=CVE-2026-107406`
- Bleeping Computer Report: `https[:]//www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/`