Skip to content
Brief Security & Trust ·

Citrix fixes critical NetScaler flaw tied to SAML login settings

The bug, CVE-2026-107406, may allow remote code execution or a crash, and no attacks using it have been reported.

In brief
  • Citrix fixed CVE-2026-107406 in NetScaler ADC and Gateway. It affects devices set up for SAML sign-in.
  • The Hacker News says no attacks using it have been seen, but three other NetScaler flaws are being exploited.

Citrix has released fixes for a critical flaw in NetScaler ADC and NetScaler Gateway, according to its security bulletin. The flaw is tracked as CVE-2026-107406. The Hacker News reported on 9 October that Citrix calls it a memory overflow bug. Under specific settings, it may lead to remote code execution or a denial of service, meaning the device stops working. The Hacker News gave it a severity score of 9.5 out of 10. Only devices set up for SAML, a single sign-on standard, are exposed. Fixed releases start at 14.1-73.46 and 13.1-64.29, with separate FIPS builds.

The Hacker News said there is no evidence that anyone has exploited this flaw in the wild. The sources do not explain how an attacker would use the bug. Credit for finding it differs between the two reports. Citrix names Joshua Foote, Michael Tucker and Eugene Lim of the JPMorgan Chase XOR Team. The Hacker News says Citrix credited Michael Tucker, Chew Keong Tan and Alex Bernier of that team, plus Maxim Suhanov. The Hacker News also reported that three other NetScaler flaws are being exploited now.

Teams that run their own NetScaler appliances should check whether they use SAML, since Citrix ties the flaw to those settings. Citrix says Secure Private Access Hybrid setups using NetScaler are affected too, while Cloud Software Group updates Citrix-managed cloud services itself.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Citrix.