Citrix urges patching a NetScaler RCE flaw that hits SAML-configured appliances
On October 9, 2026, Citrix shipped a fix for CVE-2026-107406, a memory-overflow bug that lets an attacker run code remotely or crash NetScaler ADC and Gateway appliances configured as a SAML identity provider or service provider. Upgrade to 14.1-73.46 or 13.1-64.29, or drop the SAML configuration if you do not use it.