NoticiasNews

Citrix corrige CVE-2026-107406: falla crítica (CVSS 9.5) en NetScaler con SAML que puede derivar en ejecución remota de códigoCitrix patches CVE-2026-107406: critical (CVSS 9.5) NetScaler SAML flaw that can lead to remote code execution

2026-10-11

Citrix publicó el 9 de octubre de 2026 un boletín de seguridad para CVE-2026-107406, una vulnerabilidad de desbordamiento de memoria con puntuación CVSS 9.5 en NetScaler ADC y NetScaler Gateway. Según The Hacker News, puede provocar ejecución remota de código o denegación de servicio “bajo condiciones específicas de configuración”. Al momento de la publicación no hay evidencia de explotación activa.

Quién está expuesto

El riesgo aplica cuando el equipo está configurado como proveedor de identidad SAML (IdP) o como proveedor de servicio SAML (SP); los despliegues híbridos de Secure Private Access con NetScaler también están afectados. Para verificarlo, los administradores deben buscar las entradas authentication samlAction (SP) y authentication samlIdPProfile (IdP) en la configuración.

Versiones corregidas

  • NetScaler ADC/Gateway 14.1-73.46 y posteriores.
  • NetScaler ADC/Gateway 13.1-64.29 y posteriores.
  • NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS y posteriores.
  • NetScaler ADC 13.1-FIPS y 13.1-NDcPP 13.1.37.283 y posteriores.

Qué hacer

Identifique todos los NetScaler expuestos a internet, confirme si usan SAML, aplique la versión corregida cuanto antes y revise registros de autenticación. Por el historial reciente de fallas explotadas en este producto, conviene no esperar a que aparezca en el catálogo KEV de CISA.

En TEKFENIX desarrollamos software a medida e integraciones que dependen de pasarelas de autenticación como esta. Nuestros productos Nexturno, Servigo365 y CumplimientoControl se despliegan con control de acceso y trazabilidad, y podemos apoyar a su equipo en la revisión de arquitectura de identidad y en un plan de parcheo para infraestructura crítica.

Fuente: The Hacker News, “Citrix Patches Critical NetScaler Flaw” (9 de octubre de 2026) y boletín de seguridad de Citrix para CVE-2026-107406.

On October 9, 2026, Citrix published a security bulletin for CVE-2026-107406, a memory-overflow vulnerability with a CVSS score of 9.5 in NetScaler ADC and NetScaler Gateway. According to The Hacker News, it can lead to remote code execution or denial of service “under specific configuration conditions.” There is no evidence of active exploitation at the time of publication.

Who is exposed

The risk applies when the appliance is configured as a SAML identity provider (IdP) or SAML service provider (SP); Secure Private Access hybrid deployments using NetScaler are also affected. To check, administrators should look for authentication samlAction (SP) and authentication samlIdPProfile (IdP) entries in the configuration.

Fixed versions

  • NetScaler ADC/Gateway 14.1-73.46 and later.
  • NetScaler ADC/Gateway 13.1-64.29 and later.
  • NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later.

What to do

Inventory all internet-facing NetScaler devices, confirm whether they use SAML, apply the fixed build as soon as possible and review authentication logs. Given the recent history of exploited flaws in this product, it is wise not to wait for it to appear in CISA's KEV catalog.

At TEKFENIX we build custom software and integrations that depend on authentication gateways like this one. Our products Nexturno, Servigo365 and CumplimientoControl are deployed with access control and traceability, and we can support your team with an identity-architecture review and a patching plan for critical infrastructure.

Source: The Hacker News, “Citrix Patches Critical NetScaler Flaw” (October 9, 2026) and Citrix's security bulletin for CVE-2026-107406.

← Volver al blog← Back to blog