Full Report
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
Analysis Summary
# Vulnerability: Citrix NetScaler Memory Overflow in SAML Deployments
## CVE Details
- **CVE ID:** CVE-2026-107406
- **CVSS Score:** 9.5 (Critical)
- **CWE:** Memory Overflow (specific CWE not provided, likely CWE-120 or CWE-122)
## Affected Systems
- **Products:** NetScaler ADC, NetScaler Gateway, and Secure Private Access Hybrid deployments utilizing affected NetScaler instances.
- **Versions:**
- NetScaler ADC & Gateway: 14.1 (before 14.1-73.46) and 13.1 (before 13.1-64.29).
- NetScaler ADC FIPS: 14.1-FIPS (before 14.1-73.46 FIPS) and 13.1-FIPS/NDcPP (before 13.1-37.283).
- **Configurations:** The vulnerability is only present when the appliance is configured as a:
- **SAML Identity Provider (IdP)**
- **SAML Service Provider (SP)**
## Vulnerability Description
CVE-2026-107406 is a critical memory overflow vulnerability. The flaw exists within the SAML processing logic of the NetScaler ADC and Gateway. Under specific configuration conditions—specifically when the device is handling SAML authentication workflows—an attacker can trigger a memory corruption state. This can lead to a complete system crash (Denial of Service) or allow the attacker to execute arbitrary code (Remote Code Execution) with the privileges of the affected process.
## Exploitation
- **Status:** Not exploited in the wild (at the time of reporting).
- **Complexity:** Medium (requires specific SAML configurations).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for full system compromise via RCE).
- **Integrity:** High (Unauthorized modification of system state/data).
- **Availability:** High (Can trigger Denial of Service).
## Remediation
### Patches
Citrix recommends upgrading to the following versions or later:
- NetScaler ADC and Gateway: **14.1-73.46**
- NetScaler ADC and Gateway: **13.1-64.29**
- NetScaler ADC 14.1-FIPS: **14.1-73.46 FIPS**
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: **13.1.37.283**
### Workarounds
No specific functional workarounds were provided other than disabling SAML capabilities; however, this would break authentication for many environments. Immediate patching is the primary recommended mitigation.
## Detection
### Indicators of Compromise
To determine if a system is in a vulnerable configuration, administrators should check the running configuration for the following commands:
- **SAML SP Check:** `add authentication samlAction`
- **SAML IdP Check:** `add authentication samlIdPProfile`
### Detection methods and tools
- **Log Analysis:** Monitor for unusual crashes in authentication processes or memory allocation errors in system logs.
- **Vulnerability Scanning:** Use updated security scanners to identify NetScaler versions below the patched thresholds.
## References
- **Vendor Advisory:** [https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191)
- **Citrix TechZone Blog:** [https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/](https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/)
- **News Source:** [https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html](https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html)