CVE-2026-107406EPSS p38.9%
CVE-2026-107406CVE-2026-107406
Description
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
* For the following versions: Applicable only when configured as a SAML IdP:
* NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
* NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
* NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
* NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive
For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
* NetScaler ADC and NetScaler Gateway before 14.1-73.37
* NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
* NetScaler ADC and NetScaler Gateway before 13.1-64.23
* NetScaler ADC 13.1-FIPS before13.1-NDcPP 13
Scoring
| EPSS | 0.47% probability of exploitation · percentile 38.9% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-10 |