Critical severityNVD Advisory· Published Oct 8, 2026
CVE-2026-107406
CVE-2026-107406
Description
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
- For the following versions: Applicable only when configured as a SAML IdP:
- NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
- NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
- NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
- NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive
For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
- NetScaler ADC and NetScaler Gateway before 14.1-73.37
- NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- NetScaler ADC and NetScaler Gateway before 13.1-64.23
- NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279
Affected products
3- Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive; before 14.1-73.37; before 14.1-73.37 FIPS; before 13.1-64.23; before 13.1-NDcPP 13.1-37.279
- Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; before 14.1-73.37; before 13.1-64.23
- Range: between 14.1-73.37 and 14.1-73.41, inclusive; between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive; between 13.1-64.23 and 13.1-64.28, inclusive; between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive; before 14.1-73.37; before 14.1-73.37 FIPS; before 13.1-64.23; before 13.1-NDcPP 13.1-37.279
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.