News · Science & Technology
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix patched CVE-2026-107406, a memory overflow vulnerability rated critical. Under specific configuration conditions, it could let an attacker execute code remotely or cause a denial-of-service. The affected products are NetScaler ADC and NetScaler Gateway, including certain 14.1, 13.1, and FIPS releases. The key condition is SAML use. A deployment may be exposed when configured as a SAML identity provider, service provider, or both, depending on the version. Administrators can check for configuration entries such as “add authentication samlAction” or “add authentication samlIdPProfile.” Secure Private Access Hybrid deployments using NetScaler instances are also affected. Citrix fixed the issue in 14.1-73.46 and later, 13.1-64.29 and later, and corresponding FIPS releases. Citrix reported no evidence of exploitation in the wild. Customers should identify affected configurations and upgrade to the recommended versions.
Based on reporting by The Hacker News
What vulnerability did Citrix patch, and which NetScaler products and SAML configurations are affected?
Citrix patched CVE-2026-107406, a memory overflow vulnerability rated critical. Under specific configuration conditions, it could let an attacker execute code remotely or cause a denial-of-service. The affected products are NetScaler ADC and NetScaler Gateway, including certain 14.1, 13.1, and FIPS releases.
The key condition is SAML use. A deployment may be exposed when configured as a SAML identity provider, service provider, or both, depending on the version. Administrators can check for configuration entries such as “add authentication samlAction” or “add authentication samlIdPProfile.” Secure Private Access Hybrid deployments using NetScaler instances are also affected.
Citrix fixed the issue in 14.1-73.46 and later, 13.1-64.29 and later, and corresponding FIPS releases. Citrix reported no evidence of exploitation in the wild. Customers should identify affected configurations and upgrade to the recommended versions.
What are remote code execution and denial-of-service, the two outcomes this flaw could cause?
Remote code execution means an attacker can make a vulnerable system run instructions of the attacker’s choosing from a remote location. In this case, successful exploitation could allow code to run on a NetScaler appliance without the attacker having normal administrative access. That can turn a network device into a foothold for further activity.
Denial-of-service means making a system or service unavailable to legitimate users. A successful attack might crash or disrupt the vulnerable NetScaler, preventing it from handling its expected traffic or authentication functions. The article identifies both outcomes as possible results of CVE-2026-107406.
The exact result depends on the specific conditions of exploitation. Citrix describes the flaw as a memory overflow and says it affects certain SAML configurations. The vulnerability has a CVSS score of 9.5, but Citrix reported no evidence that it had been exploited in the wild.
How severe is a CVSS score of 9.5 out of 10, and what does that score measure?
A CVSS score of 9.5 out of 10.0 falls in the critical range. It signals that a vulnerability can present a very serious security risk, especially when the affected system supports important network or authentication functions. The score is a prioritization tool, not a prediction that every affected organization will be attacked.
CVSS measures factors such as how an attacker might reach and exploit a flaw, whether authentication or user interaction is needed, and what could happen to confidentiality, integrity, and availability. The article gives the score for CVE-2026-107406 and describes possible outcomes as remote code execution or denial-of-service.
The score should be considered alongside deployment details. Exploitation depends on NetScaler being configured as a SAML identity provider or service provider. Citrix said there was no evidence of exploitation in the wild, but the 9.5 rating makes reviewing configurations and applying patches urgent.
What could happen to an organization if an attacker successfully exploited this vulnerability?
If exploited successfully, CVE-2026-107406 could give an attacker the ability to execute code remotely on a NetScaler appliance. That could compromise a device positioned in front of applications or involved in authentication. The flaw could also cause denial-of-service, making the appliance unavailable or disrupting its operations.
The article does not describe a specific attack sequence or business impact for individual organizations. It does establish that exploitation requires certain SAML configurations. NetScaler deployments acting as SAML identity providers or service providers are the relevant cases, and Secure Private Access Hybrid deployments using NetScaler are also affected.
Possible organizational effects include interrupted access to protected services, disrupted authentication flows, or broader security concerns if code executes on the appliance. Citrix reported no evidence of exploitation in the wild. The recommended response is to check configurations and upgrade to fixed versions.
Why does configuring NetScaler as a SAML identity provider or service provider determine whether the flaw can be exploited?
Configuration determines exploitability because CVE-2026-107406 affects a memory-handling path associated with SAML operation. A NetScaler deployment configured as a SAML identity provider or service provider uses the relevant functions. Deployments without those roles may not meet the conditions Citrix identifies for exploitation.
Administrators can inspect configuration entries to determine whether the roles are enabled. Citrix lists “add authentication samlAction” for a SAML service provider and “add authentication samlIdPProfile” for a SAML identity provider. The affected release ranges differ depending on whether the appliance is configured as an IdP, an SP, or both.
This condition narrows the vulnerable exposure but does not remove the need to patch. Citrix specifically warns that Secure Private Access Hybrid deployments using NetScaler are affected. Customers should identify the role in use, compare the appliance version with Citrix’s affected ranges, and upgrade accordingly.
What is SAML, and how do identity providers and service providers use it to enable single sign-on?
SAML, or Security Assertion Markup Language, is a framework for exchanging authentication and authorization information between systems. It commonly supports single sign-on, allowing a user to authenticate once and then access another application without signing in again. The article discusses NetScaler deployments that use SAML roles.
The identity provider authenticates the user and creates a signed statement, called an assertion, about that authentication. The service provider receives and validates the assertion before allowing access to its application or service. In some deployments, NetScaler can perform either role. Citrix identifies these roles as the configurations that determine exposure to the flaw.
The article does not explain SAML’s protocol details, but it confirms that affected NetScaler systems can be configured as a SAML IdP or SP. Administrators can check entries such as “samlAction” and “samlIdPProfile,” then upgrade affected systems to Citrix’s recommended releases.
What does a NetScaler application delivery controller do, and how can a memory overflow in such a system lead to code execution?
An application delivery controller sits between users and applications, helping deliver services and manage network traffic. NetScaler ADC is such a platform, while NetScaler Gateway supports access to protected resources. The article focuses on a memory overflow in these products when particular SAML configurations are enabled.
A memory overflow occurs when software writes more data than a memory area can safely hold. The excess data can overwrite nearby information, potentially changing how the program behaves. If an attacker can control that data and the affected code path, the altered memory may cause the system to run attacker-provided instructions. The article identifies remote code execution and denial-of-service as possible outcomes.
The exact exploit method is not provided. Citrix says exploitation requires specific SAML IdP or SP configurations and affects listed release ranges. Fixed versions include 14.1-73.46 and later, and 13.1-64.29 and later, plus corresponding FIPS releases.
Key Facts:
📌 CVE-2026-107406 is a critical memory overflow vulnerability.
📌 SAML IdP and SP configurations determine exposure.
📌 Citrix fixed the flaw in newer NetScaler releases.
📌 Remote code execution lets attackers run instructions on a vulnerable system.
📌 Denial-of-service disrupts availability for legitimate users.
📌 CVE-2026-107406 could cause either outcome.
📌 CVE-2026-107406 has a CVSS score of 9.5 out of 10.0.