Citrix has rolled out updates to fix a critical vulnerability affecting its NetScaler ADC and NetScaler Gateway products. This flaw, identified as CVE-2026-107406, holds the potential to enable remote code execution (RCE) or trigger denial-of-service (DoS) attacks under specific configurations.
Understanding the Vulnerability
The vulnerability in question is a memory overflow issue, which Citrix has rated with a CVSS score of 9.5, indicating its severe impact. Importantly, there have been no known instances of this flaw being exploited in real-world scenarios. Credit for discovering and reporting the issue goes to Michael Tucker, Chew Keong Tan, and Alex Bernier from the JPMorgan Chase XOR Team, alongside Maxim Suhanov.
The flaw specifically impacts NetScaler configurations set up as a SAML identity provider (IdP) or service provider (SP). Customers are advised to inspect their configurations for relevant entries such as ‘add authentication samlAction’ for SAML SP or ‘add authentication samlIdPProfile’ for SAML IdP.
Affected Versions and Configurations
This security issue affects various versions of NetScaler ADC and NetScaler Gateway. Specifically, it impacts versions configured as a SAML IdP, including versions between 14.1-73.37 and 14.1-73.41, as well as versions configured as a SAML SP or IdP before 14.1-73.37. Secure Private Access Hybrid deployments utilizing these setups are also at risk.
Citrix emphasizes the necessity for customers to upgrade their systems to the recommended versions to mitigate the vulnerability’s threat. The corrected versions include Citrix NetScaler ADC and Gateway 14.1-73.46 and later, as well as 13.1-64.29 and subsequent releases for 13.1.
Security Patch Implementation
The company has provided updates addressing this vulnerability across its affected product lines. Customers are urged to update to Citrix NetScaler ADC and Gateway 14.1-73.46 and later, or 13.1-64.29 and subsequent releases to ensure protection against potential attacks.
This patch comes amidst active exploitation of other vulnerabilities (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) in NetScaler ADC and Gateway appliances, highlighting the critical need for timely updates and vigilant security practices.
By implementing these patches, organizations can safeguard their systems against possible breaches and ensure their security posture remains robust.
