AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107406.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.5CVSS 4.0 · 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting AnalysisModified Oct 10, 2026

Disclosure summary

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37 * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Source-reported weakness categories

CWE-119

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-107406

Open original source · Updated Oct 10, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

CSO Online · RSS-ae27286a666d1f79daef3877508994b2ecc

Open original source · Updated Oct 09, 2026

Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway

CVE mention in publisher metadata; check the original affected versions.

Malware Analysis, News and Indicators - Latest topics · RSS-95f24ec0e5c35944bfe9ee01f71bdc9493d

Open original source · Updated Oct 09, 2026

Citrix security advisory (AV26-1023)

CVE mention in publisher metadata; check the original affected versions.

NHS Digital - Cyber Alert Feed · RSS-a4b0a16def4908e9d40fb75fba08b619a05

Open original source · Updated Oct 09, 2026

CC-4865 - Critical Remote Code Execution Vulnerability in Citrix NetScaler

CVE mention in publisher metadata; check the original affected versions.

Security Affairs · RSS-b62a2e84d318ae0c744ed169418c14aff2d

Open original source · Updated Oct 09, 2026

CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability

CVE mention in publisher metadata; check the original affected versions.

The Hacker News · RSS-282fb784975a02d0f6d8bc6b486d280540e

Open original source · Updated Oct 09, 2026

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

CVE mention in publisher metadata; check the original affected versions.

SecurityWeek RSS Feed · RSS-8d2528422f22ae446c0875076d3924e6d67

Open original source · Updated Oct 09, 2026

Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

CVE mention in publisher metadata; check the original affected versions.

Original records & references

PUBLISHED 2026-10-08T18:17:26-04:00
MODIFIED 2026-10-10T00:18:09-04:00
INGESTED 2026-10-10T20:55:03-04:00