Memory Overflow Vulnerability in NetScaler ADC and Gateway by Citrix
CVE-2026-107406

9.5CRITICAL

Key Information:

Vendor

Netscaler

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107406?

A memory overflow vulnerability exists in the NetScaler ADC and Gateway products by Citrix, specifically when configured as a SAML Service Provider (SP) or Identity Provider (IdP). This flaw allows an attacker to potentially execute arbitrary code remotely or cause a denial of service, impacting the availability and security of the affected systems. The vulnerability is applicable to specific versions under particular configurations and could compromise the integrity of the affected installations.

Affected Version(s)

ADC 0 < 14.1-73.46

ADC 0 < 13.1-64.29

ADC 0 < 14.1-73.46 FIPS

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.