CVE-2026-107406
Received
Received - Intake
Memory Corruption in NetScaler ADC or Gateway
Vulnerability report for CVE-2026-107406, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: NetScaler
Description
Description
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
Β
* For the following versions: Applicable only when configured as aΒ SAML IdP:
* NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
* NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
* NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
* NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive
Β
For the following versions: Applicable only when configured as aΒ SAML SP or SAML IdP:
* NetScaler ADC and NetScaler Gateway before 14.1-73.37Β
* NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPSΒ
* NetScaler ADC and NetScaler Gateway before 13.1-64.23
* NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| NetScaler | ADC | 0 |
| NetScaler | ADC | 0 |
| NetScaler | ADC | 0 |
| NetScaler | ADC | 0 |
| NetScaler | Gateway | 0 |
| NetScaler | Gateway | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |