AI analysis
CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. It is reachable over the network without authentication or user interaction, but only when the appliance is configured as a SAML service provider or SAML identity provider, and only on the version ranges listed for each role; attack complexity is rated high. A successful attack can compromise confidentiality and integrity of the appliance and can also affect connected systems, or can crash the service. Citrix appliances in the named 14.1, 14.1-FIPS, 13.1, and 13.1-FIPS ranges are affected when those SAML roles are enabled. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade NetScaler ADC and NetScaler Gateway, including FIPS builds, to a vendor-fixed release newer than every range listed as vulnerable, and apply the advisory to both SAML service-provider and identity-provider roles. Until then, disable unused SAML SP or IdP configuration and prioritize internet-facing gateways. Confirm the running build and SAML role, and watch for crashes or unexpected management-plane behavior.
Affected
| Citrix NetScaler ADC and NetScaler Gateway | Before 14.1-73.37 when configured as a SAML SP or SAML IdP; 14.1-73.37 through 14.1-73.41 inclusive when configured as a SAML IdP |
| Citrix NetScaler ADC 14.1-FIPS | Before 14.1-73.37 FIPS when configured as a SAML SP or SAML IdP; 14.1-73.37 FIPS through 14.1-73.41 FIPS inclusive when configured as a SAML IdP |
| Citrix NetScaler ADC and NetScaler Gateway | Before 13.1-64.23 when configured as a SAML SP or SAML IdP; 13.1-64.23 through 13.1-64.28 inclusive when configured as a SAML IdP |
| Citrix NetScaler ADC 13.1-FIPS | Before 13.1-NDcPP 13.1-37.279 when configured as a SAML SP or SAML IdP; 13.1-NDcPP 13.1-37.279 through 13.1-37.282 inclusive when configured as a SAML IdP |
Description
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37 * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279