Critical Citrix NetScaler Vulnerability Allows Remote Code Execution Attacks – CVSS 9.5
Citrix disclosed CVE-2026-107406, a CVSS 9.5 NetScaler memory overflow that can allow remote code execution.
Citrix disclosed CVE-2026-107406, a critical memory-overflow flaw (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway, tracked in bulletin CTX697191 with a CVSS v4.0 score of 9.5. Under specific SAML identity-provider or service-provider configurations, an unauthenticated attacker could achieve remote code execution or denial of service; attack complexity is rated high. Citrix said it was not aware of unmitigated exploits at publication. Recommended upgrades include 14.1-73.46 or later, 13.1-64.29 or later, and matching FIPS or NDcPP fixed builds; Citrix-managed cloud and Adaptive Authentication are excluded.
- CVE-2026-107406 is a CWE-119 memory overflow scored CVSS 9.5.
- Exploitation needs no privileges or user interaction, but complexity is high.
- Exposure depends on build and SAML identity-provider or service-provider role.
- Citrix reported no known unmitigated exploits when the bulletin was published.
- Fixed builds include 14.1-73.46, 13.1-64.29, and corresponding FIPS releases.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5<1%Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107406 | Memory overflow RCE/DoS in NetScaler ADC and Gateway |
Full article482 words · extracted from gbhackers.com · click to collapse
Citrix has disclosed a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial of service under specific configuration conditions.
This vulnerability, tracked as CVE-2026-107406, carries a CVSS v4.0 base score of 9.5, prompting an urgent upgrade advisory for affected customer-managed deployments.
The security bulletin, CTX697191, identifies this weakness as CWE-119, which involves improper restriction of operations within the bounds of a memory buffer.
The severity vector indicates that exploitation requires no privileges or user interaction, although the attack complexity is high. Successful exploitation could compromise the confidentiality, integrity, and availability of vulnerable appliances.
Citrix stated that it was not aware of any unmitigated exploits when it published the bulletin. However, this does not eliminate the exposure for deployments that meet the affected software version and SAML configuration requirements. Customers should promptly review their environments.
Critical Citrix NetScaler Vulnerability
The vulnerability affects appliances configured as Security Assertion Markup Language (SAML) identity providers or service providers, with applicability varying across software releases. Administrators must evaluate both the installed build and the appliance’s SAML role to determine whether a deployment is vulnerable.
For NetScaler ADC and Gateway versions 14.1-73.37 through 14.1-73.41, the vulnerability applies only when configured as a SAML identity provider. This same restriction applies to NetScaler ADC 14.1-FIPS builds 14.1-73.37 FIPS through 14.1-73.41 FIPS.
Within the 13.1 branch, identity-provider exposure affects NetScaler ADC and Gateway builds 13.1-64.23 through 13.1-64.28. NetScaler ADC 13.1-FIPS and NDcPP builds 13.1-37.279 through 13.1-37.282 are also affected under the identity-provider configuration requirement.
Earlier supported releases have broader exposure. Builds before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 in their respective branches are vulnerable when configured as either a SAML service provider or identity provider. This distinction makes configuration validation essential when assessing affected systems.
Administrators can identify service-provider configurations by checking for the entry `add authentication samlAction` in the appliance configuration.
The presence of `add authentication samlIdPProfile` indicates an identity-provider configuration. These entries should be compared with the applicable version ranges before determining exposure.
Citrix recommends upgrading NetScaler ADC and Gateway to version 14.1-73.46 or later, or to 13.1-64.29 or later within the 13.1 branch. Customers operating NetScaler ADC 14.1-FIPS should install version 14.1-73.46 FIPS or a subsequent release.
For NetScaler ADC 13.1-FIPS and 13.1-NDcPP deployments, the recommended fixed build is 13.1-37.283 or later within the corresponding branch. Customers should select the appropriate update for their environment using security bulletin CTX697191.
Secure Private Access Hybrid deployments using affected NetScaler instances also require upgrades. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are excluded from this bulletin because Citrix applies the necessary software updates. Affected customers should prioritize remediation without waiting for evidence of exploitation.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.