Citrix Fixes Critical NetScaler Flaw Allowing Remote Code Execution
Original source
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
The Hacker News →Citrix has issued patches for a critical memory overflow vulnerability (CVE-2026-107406) in NetScaler ADC and NetScaler Gateway, which could enable remote code execution or denial-of-service under specific conditions. The flaw, rated 9.5 on the CVSS scale, affects systems configured as SAML identity or service providers. The issue impacts multiple versions of NetScaler software, and Citrix has provided updated versions to address the vulnerability. The flaw was discovered by researchers from JPMorgan Chase and Maxim Suhanov, with no reported exploitation in the wild.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.