External risk intelligence

NetScaler ADC SAML Memory Overflow Leading to RCE or DoS.

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-107406

NetScaler ADC and NetScaler Gateway are typically deployed as internet-facing edge appliances, load balancers, or identity gateways. When configured as a SAML Service Provider or Identity Provider, these services are designed to interact with external traffic to manage authentication and authorization flows, making them inherently public-facing in standard deployment patterns.

Remote Code Execution

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A memory overflow vulnerability has been identified in NetScaler ADC and NetScaler Gateway when configured for SAML. This could potentially allow for remote code execution or denial of service. The primary concern is confirming if your specific configurations and versions are impacted.

  • Flaw allows unauthorized code execution or service denial.
  • Critical for systems handling authentication flows.
  • Confirm impact and relevant exposure to affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could trigger this memory overflow by sending specially crafted network traffic to an exposed NetScaler ADC or Gateway. This occurs when the appliance is configured as a SAML Identity Provider or Service Provider, allowing the attacker to potentially execute code or cause a denial of service.

  • Entry condition: Network exposure.
  • Trigger point: SAML authentication flow.
  • Resulting risk: Remote code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in NetScaler ADC, when configured as a SAML SP or IdP, could allow an unauthenticated attacker to execute arbitrary code or cause a denial of service by exploiting a memory overflow. The specific versions and configurations that are vulnerable are detailed in the advisory.

  • System data could be at risk.
  • Unauthenticated network access is possible.
  • Remote code execution or service disruption may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The vulnerability impacts NetScaler ADC and NetScaler Gateway when configured for SAML, potentially affecting external-facing authentication and access control. The primary responsibility for addressing this likely falls to platform or infrastructure teams managing these appliances, in coordination with security teams and potentially vendor management if external support is required. The first practical step is to inventory all NetScaler instances, verify their SAML configuration and exposure, and identify the owning team and business criticality for prioritization.

  • Platform or Infrastructure teams own remediation.
  • Verify SAML configuration and external exposure.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is NetScaler ADC and how is it used?

NetScaler ADC is a networking appliance used as a load balancer and application delivery controller. Organizations deploy it to manage traffic and secure access to web applications. It often acts as an identity gateway, handling authentication processes to ensure users can safely access internal resources.

What does this memory overflow vulnerability mean for CVE-2026-107406?

This vulnerability involves a memory overflow flaw, where the software improperly manages memory during specific operations. If exploited, an attacker could potentially crash the system, leading to a denial of service, or execute unauthorized code on the appliance, which is the most critical outcome.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted network traffic to the device while it acts as a SAML Identity Provider or Service Provider. If the device is not configured for SAML, this specific memory overflow path is not activated.

Why should I care about this vulnerability based on Halo Surface Signal?

Halo Surface Signal identifies these devices as typically internet-facing, meaning they are designed to handle external authentication requests. Because they are often placed at the network edge to manage traffic, their exposure to the public internet makes them a high-priority target for remote attacks.

What are the first steps to secure my NetScaler environment?

Start by creating an inventory of all NetScaler instances. Verify which ones are currently configured as SAML Service Providers or Identity Providers and check their version numbers against the advisory. Once you confirm which units are impacted, coordinate with your infrastructure team to prioritize them for updates.

References