Particle.news

Citrix Issues Patch for Critical NetScaler SAML Memory Overflow

SAML IdP or SP settings determine whether a NetScaler is vulnerable so operators should inventory configurations, preserve volatile evidence before upgrading, and treat exposed devices as high risk.

Overview

  • Citrix released fixes Friday for CVE-2026-107406, a memory overflow in NetScaler ADC and Gateway that can cause remote code execution or denial of service when the appliance is configured as a SAML identity provider or service provider.
  • The company provided specific fixed builds for affected branches and urged immediate upgrades to the listed versions to stop new exploitation.
  • Citrix said it is not aware of unmitigated in-the-wild exploitation of CVE-2026-107406 but warned that earlier NetScaler flaws were actively abused to deploy web shells, tunneling tools, and techniques for persistent root access.
  • Security guidance from national CERTs and researchers calls for operators to first preserve logs and take memory dumps, then apply the patch, and to rotate credentials and keys if a prior compromise is suspected.
  • Large internet scans show tens of thousands to hundreds of thousands of externally reachable NetScaler instances, so configuration-dependent exposure creates a wide potential blast radius for both targeted attackers and opportunistic scanners.