CVE-2026-107406: Vulnerability in NetScaler ADC
Description
CVE-2026-107406 is a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway when configured as a SAML Service Provider (SP) or Identity Provider (IdP). This flaw can lead to remote code execution or denial of service. It affects multiple versions of NetScaler ADC and Gateway, specifically versions before 14.1-73.46 and 13.1-64.29, including certain FIPS variants. The vulnerability has a high CVSS 4.0 score of 9.5, indicating severe impact if exploited.
CVSS v4.0
Score 9.5critical
Affected software
NetScaler
ADC
NetScaler
Gateway
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in NetScaler ADC and NetScaler Gateway involves a memory overflow condition that can be triggered when the product is configured as a SAML SP or IdP. The affected versions include NetScaler ADC and Gateway versions prior to 14.1-73.46 and 13.1-64.29, with specific version ranges detailed for both standard and FIPS builds. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code remotely or cause a denial of service. The CVSS 4.0 vector indicates network attack vector, high complexity, no privileges or user interaction required, and high impacts on confidentiality, integrity, availability, and security scope.
Potential Impact
An attacker exploiting this memory overflow vulnerability could achieve remote code execution or cause a denial of service on affected NetScaler ADC or Gateway devices configured as SAML SP or IdP. This could lead to full compromise of the device, impacting confidentiality, integrity, and availability of services relying on these devices.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, organizations should review their NetScaler ADC and Gateway configurations, especially SAML SP and IdP settings, and apply any temporary mitigations recommended by the vendor. Monitor vendor channels for patch releases addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NetScaler
- Date Reserved
- 2026-10-08T00:18:26.020Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac80c6f2cdf04f6563805c0
Added to database: 10/08/2026, 21:34:39 UTC
Last enriched: 10/08/2026, 22:18:45 UTC
Last updated: 10/08/2026, 23:48:15 UTC
Views: 173
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.