לא נמצא חיבור אינטרנט
ניוז קליק

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments

09/10/2026-12:41 09/10/2026-12:45 מחשבים וטכנולוגיה CyberSec Guru דיווח

Citrix Patches Critical NetScaler Memory Overflow Flaw (CVSS 9.5) That Enables Remote Code Execution in SAML Deployments
CVE-2026-107406 affects SAML IdP and SP configurations, and three other NetScaler bugs are already being exploited Citrix has shipped emergency patches for a critical memory overflow in NetScaler ADC and NetScaler Gateway. Under specific configuratio
סיכום מאמר
Citrix שחרר עדכוני חירום לתיקון פגיעה קריטית בזיכרון (overflow) ב‑NetScaler ADC ו‑NetScaler Gateway, המזוהה כ‑CVE‑2026-107406 עם ציון CVSS 9.5. הפגיעה מאפשרת ביצוע קוד מרחוק (RCE) בהתקנות שבהן מופעל SAML – הן כ‑Identity Provider (IdP) והן כ‑Service Provider (SP) – כאשר תוקף שולח בקשת SAML מזויפת שמנצלת את overflow בזיכרון. בנוסף לפגיעה זו, צוין כי שלוש פגיעות נוספות ב‑NetScaler מנוצלות כבר בשטח, מה שמגביר את הדחיפות ליישום התיקונים. העדכונים זמינים לגרסאות NetScaler 13.0‑build xx ו‑13.1‑build xx ומטפ
תוכן זה נוצר על ידי בינה מלאכותית.

עוד מאמרים בנושא