Citrix Fixes Critical NetScaler Flaw That Could Allow Remote Takeover in SAML Setups
Citrix has released patches for another critical security flaw affecting NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-107406, it is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions. It has a CVSS score of 9.5 out of 10. Citrix says there is no evidence the issue has been exploited in the wild.
Exploitation depends on how the appliance is set up. Affected deployments are those configured as a SAML identity provider (IdP) or service provider (SP). Citrix advises customers to check their configuration to see whether their instances meet these criteria. Secure Private Access Hybrid deployments that use NetScaler instances are also affected, and Citrix says customers need to upgrade those instances to the recommended NetScaler versions. The flaw was reported by Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov.
The news arrives at a tense time for NetScaler users. Three other flaws in NetScaler ADC and NetScaler Gateway appliances (CVE 2026-88771, CVE 2026-88772 and CVE 2026-88779) are already under active exploitation in the wild. This article covers only the opening of the original report, so businesses should consult Citrix's advisory for the full list of affected and fixed versions.