Source: The Hacker News, Citrix security advisory
Citrix has published patches for a new critical vulnerability affecting NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-107406 and carrying a CVSS score of 9.5 out of 10, the flaw is a memory overflow that may lead to remote code execution or denial of service when the appliances are configured as a SAML identity provider or service provider. Citrix credits researchers from the JPMorgan Chase XOR Team and independent researcher Maxim Suhanov with the discovery, and says there is currently no evidence of exploitation in the wild.
Who is affected
The vulnerability matters for any organization whose NetScaler deployment handles SAML traffic, which in practice means most enterprise single sign-on setups that front authentication through Citrix. Affected configurations include SAML service provider setups using “add authentication samlAction” and SAML identity provider setups using “add authentication samlIdPProfile”. Secure Private Access Hybrid deployments that use NetScaler instances are also affected. Fixed versions include NetScaler ADC and Gateway 14.1-73.46 and later, 13.1-64.29 and later, plus the corresponding FIPS builds.
The timing makes this urgent
This patch lands while three other NetScaler flaws, CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779, are already being exploited in the wild, as we noted in our earlier coverage of the NetScaler SAML zero-day. NetScaler appliances are a favorite target precisely because they sit at the edge and hold the keys to enterprise authentication. If your SAML identity infrastructure is exposed and unpatched, an attacker who reaches it can potentially achieve code execution and pivot into your identity layer.
The practical advice is straightforward: inventory your NetScaler instances, check whether they carry SAML IdP or SP configurations, and upgrade to the fixed builds now, before this flaw joins the exploited list. If you need help auditing your Citrix estate or hardening your SSO architecture, contact Excello Digital at https://excello.digital/contact/. We help organizations patch, segment and monitor the infrastructure that guards their logins.
