Site icon VMVirtualMachine.com

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

By The Hacker News
Publication Date: 2026-10-09 08:11:00

Ravie LakshmananOct 09, 2026Vulnerability / Network Security

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.

“CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions,” Citrix said.

The vulnerability carries a CVSS score of 9.5 out of 10.0. There is no evidence that the issue has been exploited in the wild. Citrix has credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting the flaw.

Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP). Customers can determine if their instances meet the criteria by checking the configuration for entries like below –

    …

Exit mobile version