Critical Remote Code Execution Vulnerability in Citrix NetScaler ADC and Gateway (CVE‑2026‑107406)
What It Is – Citrix disclosed CVE‑2026‑107406, a memory‑overflow flaw in NetScaler ADC and NetScaler Gateway that can lead to remote code execution (RCE) or denial‑of‑service (DoS) when the appliance is configured as a SAML Service Provider or Identity Provider.
Exploitability – CVSS v4.0 base score 9.5 (Critical). No public exploits have been observed, but the vulnerability is weaponizable once a vulnerable configuration exists.
Affected Products – Citrix NetScaler ADC and NetScaler Gateway versions 13.1‑64.29, 14.1‑73.46 and later (including FIPS builds).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability‑management evidence: timely patching is a core control that satisfies multiple framework objectives (e.g., NIST CSF DE.CM‑1, ISO 27001 A.12.6).
- Provides a concrete audit trail: patch‑deployment records, configuration checks, and post‑patch validation become defensible proof of due diligence.
- Highlights the importance of secure configuration monitoring; a mis‑configured SAML setting can turn a routine appliance into an RCE vector, underscoring the value of continuous control mapping.
Recommended Actions
- Apply the Citrix security updates for the affected NetScaler versions immediately.
- Verify that the appliance is not unintentionally configured as a SAML SP/IdP, or disable SAML if not required.
- Update your asset inventory and vulnerability‑management dashboard to reflect the new CVE and patch status.
- Enable logging of SAML‑related configuration changes and monitor for anomalous activity.