Full Report
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]
Analysis Summary
# Vulnerability: Citrix NetScaler RCE and DoS Flaw (CVE-2026-107406)
## CVE Details
- **CVE ID:** CVE-2026-107406
- **CVSS Score:** Critical (Numerical score not explicitly provided in text, but categorized as "Critical")
- **CWE:** Memory Overflow (e.g., CWE-119 or CWE-120)
## Affected Systems
- **Products:**
- NetScaler ADC
- NetScaler Gateway
- **Versions:**
- NetScaler ADC and NetScaler Gateway: Earlier than 14.1-73.46
- NetScaler ADC and NetScaler Gateway: Earlier than 13.1-64.29
- NetScaler ADC 14.1-FIPS: Earlier than 14.1-73.46 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: Earlier than 13.1.37.283
- **Configurations:** Systems must be configured as a **SAML Identity Provider (IdP)** or a **SAML Service Provider (SP)** to be vulnerable.
## Vulnerability Description
CVE-2026-107406 is a memory overflow vulnerability. The flaw exists within the handling of SAML configurations on NetScaler appliances. An attacker can exploit this overflow to achieve Remote Code Execution (RCE) on the targeted device. Additionally, the flaw can be used to trigger a Denial-of-Service (DoS) state, leading to system crashes.
## Exploitation
- **Status:** Not exploited (As of the publication date, Citrix is not aware of any unmitigated exploits in the wild).
- **Complexity:** Low (Implied by the urgency of the critical rating for RCE).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for full system takeover and credential theft).
- **Integrity:** High (Potential for deployment of web shells and tunneling malware).
- **Availability:** High (Can trigger a denial-of-service/system crash).
## Remediation
### Patches
Citrix recommends upgrading to the following versions or later:
- NetScaler ADC and NetScaler Gateway **14.1-73.46**
- NetScaler ADC and NetScaler Gateway **13.1-64.29**
- NetScaler ADC **14.1-FIPS 14.1-73.46 FIPS**
- NetScaler ADC **13.1-FIPS and 13.1-NDcPP 13.1.37.283**
### Workarounds
No specific configuration workarounds were provided in the article; immediate patching is the primary recommended mitigation. If patching is delayed, administrators should consider disabling SAML IdP/SP features if they are not mission-critical, though this may impact production services.
## Detection
- **Indicators of Compromise:** Look for unusual crashes in NetScaler processes or unauthorized changes to system files.
- **Detection methods and tools:**
- Monitor for large or malformed SAML requests.
- Audit logs for unexpected administrative access or the presence of custom web shells.
- Use Shadowserver fingerprints to identify if your organization's NetScaler instances are exposed externally.
## References
- **Vendor Advisory:** [https[:]//support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191]
- **Citrix Community Guidance:** [https[:]//community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/]
- **CISA Known Exploited Vulnerabilities Catalog:** [https[:]//www.cisa.gov/known-exploited-vulnerabilities-catalog]