Citrix Discloses Severe NetScaler Flaw Allowing Remote Code Execution

Citrix has disclosed CVE-2026-107406, a critical memory overflow in NetScaler ADC and NetScaler Gateway appliances used in certain SAML authentication configurations. The vulnerability has a CVSS v4.0 score of 9.5 and may let an unauthenticated remote attacker run arbitrary code or cause a denial of service. The affected products and SAML role requirements make the issue especially notable.
Citrix’s advisory, CTX697191, was released on October 8, 2026, and identifies CVE-2026-107406 as a memory overflow in NetScaler ADC and Gateway. The issue affects appliances set up for particular SAML authentication roles, with exposure varying by build and whether the system acts as a SAML service provider or identity provider.
Because these appliances often sit at the network edge, they manage authentication, deliver applications, and support remote connectivity. Citrix rated the flaw 9.5 under CVSS v4.0 and said at disclosure it had no knowledge of unmitigated exploitation. Immediate upgrades were urged.
Organizations relying on NetScaler for remote access and identity could face heightened risk if vulnerable SAML configurations remain unpatched. A successful attack may expose authentication pathways or disrupt access to internal applications, affecting employees, partners, and customers who depend on those services. Because these systems often sit at the perimeter, compromise could have downstream effects on enterprise networks and sensitive resources. The severity score and remote, unauthenticated nature may make prompt patching a priority for affected administrators.