Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-107406
Published: October 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Citrix NetScaler ADC and Citrix NetScaler Gateway when the appliance is configured as a SAML service provider or identity provider, subject to version-specific configuration requirements. A remote attacker can send specially crafted authentication requests to the affected system, trigger buffer overflow and execute arbitrary code with elevated privileges.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-107406
Citrix NetScaler Gateway - addressed in versions 13.1-64.29, 14.1-73.46