Citrix urges immediate patching of critical NetScaler SAML flaw enabling RCE
Citrix has fixed CVE-2026-107406, a CVSS 9.5 memory overflow in NetScaler ADC and Gateway appliances configured for SAML that could lead to remote code execution or denial of service.
At a glance
- CVE-2026-107406 is a memory overflow rated 9.5 on CVSS, according to The Hacker News.
- Only appliances configured as a SAML identity provider or service provider are affected.
- Fixed builds include NetScaler ADC and Gateway 14.1-73.46 and 13.1-64.29 and later.
- Citrix says it is not aware of in-the-wild exploitation, but three other NetScaler flaws are being exploited.
Citrix is urging administrators to immediately update NetScaler ADC and NetScaler Gateway appliances after patching a critical memory overflow vulnerability, tracked as CVE-2026-107406, that could allow remote code execution or denial of service on devices configured for SAML authentication. According to The Hacker News, the flaw carries a CVSS score of 9.5. The fix arrives only days after Citrix shipped emergency updates for another NetScaler zero-day, making this the latest in a string of urgent patches for the product line.
What happened
Citrix published security bulletin CTX697191 on October 9, warning that the memory overflow "may lead to remote code execution or denial-of-service under specific configuration conditions," as quoted by The Hacker News. BleepingComputer reported that the company asked customers to review the advisory and upgrade affected instances as soon as possible. SecurityWeek also reported that Citrix is urging immediate patching.
According to the bulletin cited by both outlets, Citrix is not aware of any exploitation of CVE-2026-107406 at the time of publication. The Hacker News credited the discovery to Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, as well as Maxim Suhanov.
Technical details
The vulnerability is only reachable when an appliance is configured as a SAML identity provider (IdP) or SAML service provider (SP). The Hacker News reported that administrators can check their configuration for the strings add authentication samlAction (SP) and add authentication samlIdPProfile (IdP).
Versions affected when configured as a SAML IdP include NetScaler ADC and Gateway 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28, plus the corresponding FIPS and NDcPP builds. Older releases, before 14.1-73.37 and before 13.1-64.23, are affected when configured as either an IdP or SP. Secure Private Access Hybrid deployments that use NetScaler instances are also affected, according to The Hacker News.
Who is affected
BleepingComputer, citing Shadowserver data, said more than 21,000 internet-exposed IP addresses are fingerprinted as NetScaler, including roughly 1,500 Gateway and nearly 20,000 ADC instances, though it is unclear how many are patched, honeypots or not configured for SAML.
The risk is heightened by recent history. The Hacker News noted that CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779 are all under active exploitation. BleepingComputer added that CISA has flagged 27 actively exploited Citrix vulnerabilities since November 2021, seven of which were used in ransomware attacks.
What to do
Citrix says customers need to upgrade to fixed releases: NetScaler ADC and Gateway 14.1-73.46 and later, 13.1-64.29 and later 13.1 releases, NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later. Organizations that use SAML on NetScaler should prioritize these devices, and teams that applied the earlier October emergency builds should confirm they are now on the newest versions rather than assuming they are covered.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



