CVE-2026-107406 PUBLISHED

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

Assigner: NetScaler
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:

  • For the following versions: Applicable only when configured as a SAML IdP:
  • NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
  • NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
  • NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
  • NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive

For the following versions: Applicable only when configured as a SAML SP or SAML IdP:

  • NetScaler ADC and NetScaler Gateway before 14.1-73.37 
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS 
  • NetScaler ADC and NetScaler Gateway before 13.1-64.23
  • NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
CVSS Score: 9.5

Product Status

Vendor NetScaler
Product ADC
Versions Default: unaffected
  • affected from 0 to 14.1-73.46 (excl.)
  • affected from 0 to 13.1-64.29 (excl.)
  • affected from 0 to 14.1-73.46 FIPS (excl.)
  • affected from 0 to 13.1.37.283 FIPS (excl.)
Vendor NetScaler
Product Gateway
Versions Default: unaffected
  • affected from 0 to 14.1-73.46 (excl.)
  • affected from 0 to 13.1-64.29 (excl.)

References