NetScaler builds that fixed zero-days carry critical flaw, too
What happened
Key points Citrix has disclosed CVE-2026-107406 (the public catalogue number for a specific software flaw), a critical memory overflow in NetScaler ADC and Gateway builds that patched last month's exploited flaws, scoring 9.5 on CVSS v4.0. Citrix has disclosed yet another critical vulnerability in its NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances, this time in the builds that closed last month's actively exploited flaws.
Separate SAML flaw rated as 9.5 out of 10.0. Home News Technology Security NetScaler builds that fixed zero-day (a flaw already being used in attacks before a fix exists)s carry critical flaw, too By Juha Saarinen Oct 12 2026 12:29AM Separate SAML flaw rated as 9.5 out of 10.0.
Appliances configured for SAML single sign-on as an identity provider, service provider, or both, depending on build, are exposed to remote code execution (running programs on a machine from somewhere else) or denial of service, with no workaround listed. It marks the third NetScaler security bulletin in under a fortnight and the fourth SAML-related flaw in NetScaler since March. It carries a CVSS v4.0 base score of 9.5 out of 10.0 and is rated critical.
Sources & evidence
- iTnews Reporting source
NetScaler builds that fixed zero-days carry critical flaw, too ↗
https://www.itnews.com.au/news/netscaler-builds-that-fixed-zero-days-carry-critical-flaw-too-629542