VYPR
Critical severityNVD Advisory· Published Oct 8, 2026

CVE-2026-107406

CVE-2026-107406

Description

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:

  • For the following versions: Applicable only when configured as a SAML IdP:
  • NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
  • NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
  • NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
  • NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive

For the following versions: Applicable only when configured as a SAML SP or SAML IdP:

  • NetScaler ADC and NetScaler Gateway before 14.1-73.37
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
  • NetScaler ADC and NetScaler Gateway before 13.1-64.23
  • NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Affected products

3
  • Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive; before 14.1-73.37; before 14.1-73.37 FIPS; before 13.1-64.23; before 13.1-NDcPP 13.1-37.279
  • Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; before 14.1-73.37; before 13.1-64.23
  • Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive; before 14.1-73.37; before 14.1-73.37 FIPS; before 13.1-64.23; before 13.1-NDcPP 13.1-37.279

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.