hacker-news · Crawled Oct 9, 2026
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Read original article ↗AI Summary
Citrix has patched a critical vulnerability, CVE-2026-107406, in NetScaler ADC and NetScaler Gateway appliances that could allow remote code execution or denial-of-service when the devices are configured as SAML identity providers or service providers. The flaw, which has a CVSS score of 9.5, is memory overflow-based and requires specific SAML-related configurations to be exploitable. While there is no evidence of active exploitation to date, Citrix warns that Secure Private Access Hybrid deployments are also affected and must be upgraded to patched versions to mitigate risk.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.