hacker-news · Crawled Oct 9, 2026

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Read original article ↗

AI Summary

Citrix has patched a critical vulnerability, CVE-2026-107406, in NetScaler ADC and NetScaler Gateway appliances that could allow remote code execution or denial-of-service when the devices are configured as SAML identity providers or service providers. The flaw, which has a CVSS score of 9.5, is memory overflow-based and requires specific SAML-related configurations to be exploitable. While there is no evidence of active exploitation to date, Citrix warns that Secure Private Access Hybrid deployments are also affected and must be upgraded to patched versions to mitigate risk.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.