Photo by Andrew Leu on Unsplash. Source: https://unsplash.com/photos/man-standing-near-the-control-panel--6L78OUtJmY (Unsplash License).

Citrix has now taken three fixes on the same SAML path in under two weeks, and the newest one does not cover every case.

  • CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway, rated 9.5 and filed as CWE-119.
  • Only appliances configured as a SAML service provider or an identity provider are in scope.
  • Builds from 14.1-73.37 to 73.41 and 13.1-64.23 to 64.28 are affected only as an identity provider.
  • Older builds are affected in either role. The fix is 14.1-73.46 or 13.1-64.29 and later.
  • The 27 September and 4 October flaws in the same family are exploited in the wild and on the federal known exploited list.

Check the appliance role before the version, then hunt for persistence if one of the earlier flaws got in. Read the full analysis.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.