Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability identified below
|
|
Description | Pre-conditions | CWE | CVSSv4 |
| CVE-2026-107406 | Memory overflow vulnerability leading to Remote Code Execution or Denial of Service |
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
For the following versions: Applicable only when configured as a SAML IdP:
For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
|
CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer | CVSS v4.0 Base Score: 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L) |
Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the following updated versions as soon as possible:
Instructions:
Customers can determine whether their NetScaler deployment is configured as a SAML identity provider (IdP) or service provider (SP) by checking its configuration for entries matching either of the following:
add authentication samlActionadd authentication samlIdPProfile(Note: For version-specific requirements, see the “Affected Versions” section above.)
Cloud Software Group acknowledges Joshua Foote, Michael Tucker, and Eugene Lim from the XOR Team at JPMorgan Chase for working with us to protect our customers.
Severity - Critical
A vulnerability has been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.
The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability if they meet the following conditions:
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
For the following versions: Applicable only when configured as a SAML IdP:
For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
Additional Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. Customers need to upgrade these NetScaler instances to the recommended NetScaler versions to address the vulnerability.
This bulletin only applies to customer-managed Citrix NetScaler ADC (“NetScaler ADC”) and Citrix NetScaler Gateway (“NetScaler Gateway”). Cloud Software Group upgrades the Citrix-managed cloud services and Citrix-managed Adaptive Authentication with the necessary software updates.
Cloud Software Group team has published a related blog at: https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/ which contains further context.
Citrix is notifying customers and channel partners about this potential security issue through the publication of this security bulletin on the Citrix Knowledge Center at https://support.citrix.com/support-home/topic-article-list?trendingCategory=20&trendingTopicName=Security%20Bulletin
If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at https://support.citrix.com/support-home/home
Citrix strongly recommends that all customers subscribe to receive alerts when a Citrix security bulletin is created or modified at https://support.citrix.com/wolken-support/view/aboutsupport/my-support-alerts
Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please see the following webpage: https://www.cloud.com/trust-center/support
| 2026-10-08 | Initial Publication |
| 2026-10-08 | Added a link to the NetScaler blog that contains further context |