VORANT. Threat Intelligence Research Sign in Create a free account

Citrix NetScaler SAML Flaw Enables RCE

high vulnerability technologyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

A remotely exploitable memory overflow in NetScaler ADC/Gateway SAML processing lets attackers run arbitrary code or cause denial of service; patches available.

NCSC-NL published an advisory describing a vulnerability in Citrix NetScaler ADC and Gateway when configured as a SAML Service Provider (SP) or Identity Provider (IdP). The flaw, tracked as CVE-2026-107406 with a CVSS v4 score of 9.5, stems from improper memory handling during SAML message processing, resulting in out-of-bounds read and write conditions. An attacker can trigger this remotely to achieve arbitrary code execution or cause a denial of service on affected devices.

Citrix has released updates to address the issue. The advisory does not indicate that the vulnerability is currently being exploited in the wild, but given NetScaler's history as a frequent target for mass exploitation campaigns, organizations running affected SAML-enabled configurations should prioritize patching. Defenders should verify NetScaler ADC/Gateway versions against Citrix's official advisory, apply the vendor-supplied updates promptly, and monitor SAML authentication endpoints for anomalous traffic or crash patterns that could indicate exploitation attempts.

Mentioned in this report

Vulnerabilities CVE-2026-107406

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0410.html

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,136 reports from 148 sources, 488 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs