Disclosure summary
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37 * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279
Source-reported weakness categories
CWE-119
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107406
Open original source · Updated Oct 10, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
CSO Online · RSS-ae27286a666d1f79daef3877508994b2ecc
Open original source · Updated Oct 09, 2026
Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway
CVE mention in publisher metadata; check the original affected versions.
Malware Analysis, News and Indicators - Latest topics · RSS-95f24ec0e5c35944bfe9ee01f71bdc9493d
Open original source · Updated Oct 09, 2026
Citrix security advisory (AV26-1023)
CVE mention in publisher metadata; check the original affected versions.
NHS Digital - Cyber Alert Feed · RSS-a4b0a16def4908e9d40fb75fba08b619a05
Open original source · Updated Oct 09, 2026
CC-4865 - Critical Remote Code Execution Vulnerability in Citrix NetScaler
CVE mention in publisher metadata; check the original affected versions.
Security Affairs · RSS-b62a2e84d318ae0c744ed169418c14aff2d
Open original source · Updated Oct 09, 2026
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
CVE mention in publisher metadata; check the original affected versions.
The Hacker News · RSS-282fb784975a02d0f6d8bc6b486d280540e
Open original source · Updated Oct 09, 2026
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
CVE mention in publisher metadata; check the original affected versions.
SecurityWeek RSS Feed · RSS-8d2528422f22ae446c0875076d3924e6d67
Open original source · Updated Oct 09, 2026
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2026-10-08T18:17:26-04:00
MODIFIED 2026-10-10T00:18:09-04:00
INGESTED 2026-10-10T20:55:03-04:00