# Citrix NetScaler SAML Flaw Enables RCE

Published: 2026-10-09 · Severity: high · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/5caaea25-d256-57a2-ba6d-14cb0ea30d5a/citrix-netscaler-saml-flaw-enables-rce

> A remotely exploitable memory overflow in NetScaler ADC/Gateway SAML processing lets attackers run arbitrary code or cause denial of service; patches available.

NCSC-NL published an advisory describing a vulnerability in Citrix NetScaler ADC and Gateway when configured as a SAML Service Provider (SP) or Identity Provider (IdP). The flaw, tracked as CVE-2026-107406 with a CVSS v4 score of 9.5, stems from improper memory handling during SAML message processing, resulting in out-of-bounds read and write conditions. An attacker can trigger this remotely to achieve arbitrary code execution or cause a denial of service on affected devices.

Citrix has released updates to address the issue. The advisory does not indicate that the vulnerability is currently being exploited in the wild, but given NetScaler's history as a frequent target for mass exploitation campaigns, organizations running affected SAML-enabled configurations should prioritize patching. Defenders should verify NetScaler ADC/Gateway versions against Citrix's official advisory, apply the vendor-supplied updates promptly, and monitor SAML authentication endpoints for anomalous traffic or crash patterns that could indicate exploitation attempts.

## Mentioned in this report

- Vulnerabilities: CVE-2026-107406

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0410.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5caaea25-d256-57a2-ba6d-14cb0ea30d5a/citrix-netscaler-saml-flaw-enables-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
