NEWS

Citrix Warns of New Critical NetScaler RCE Flaw in SAML Deployments

A new critical NetScaler ADC and Gateway memory-overflow flaw in SAML configurations enables RCE; Citrix urges admins to patch immediately.

Dylan H.

News Desk

October 9, 2026
4 min read
Citrix Warns of New Critical NetScaler RCE Flaw in SAML Deployments

Yet Another Critical Patch Cycle for NetScaler

Citrix has issued an urgent warning to administrators to patch NetScaler ADC and NetScaler Gateway appliances against a new critical vulnerability, tracked as CVE-2026-107406, published in bulletin CTX697191 on October 8, 2026. The flaw is a memory-overflow weakness (CWE-119) that can let an attacker achieve remote code execution or crash the appliance into a denial-of-service state. It carries a CVSS v4.0 score of 9.5.

To be vulnerable, an appliance must be configured as a SAML Identity Provider (IdP) or Service Provider (SP) — a common setup for organizations using NetScaler to broker single sign-on for internal or customer-facing applications.


AttributeValue
CVE IDCVE-2026-107406
CVSS v4.0 Score9.5
WeaknessCWE-119 — Improper Restriction of Operations within a Memory Buffer
Required ConfigurationNetScaler ADC/Gateway configured as SAML IdP or SP
BulletinCTX697191 (published October 8, 2026)
Attack VectorNetwork, no privileges or user interaction required, high attack complexity
Known ExploitationNone confirmed as of publication
CreditMichael Tucker, Chew Keong Tan, Alex Bernier (JPMorgan Chase XOR Team), Maxim Suhanov

Affected and Fixed Versions

  • Affected (IdP only), 14.1: 14.1-73.37 through 14.1-73.41
  • Affected (IdP only), 13.1: 13.1-64.23 through 13.1-64.28
  • Affected (SP or IdP), 14.1: before 14.1-73.37
  • Fixed, 14.1: 14.1-73.46 and later
  • Fixed, 13.1: 13.1-64.29 and later 13.1 releases

Citrix said it is "not aware of any unmitigated exploits of this vulnerability" as of the bulletin's publication, but urged affected customers to "review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible."

A Pattern, Not an Isolated Incident

CVE-2026-107406 is the latest in a string of serious NetScaler vulnerabilities disclosed throughout 2026, and the third in roughly two weeks. Three other flaws — CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 — have already come under active exploitation in the wild this fall. CVE-2026-88771 was an unauthenticated RCE caused by improper input validation affecting all NetScaler ADC and Gateway deployments, including default configurations, while CVE-2026-88779 was a SAML-specific zero-day exploited in targeted attacks before Citrix shipped a fix.

That means administrators who already patched for this fall's earlier zero-days still need to separately verify their SAML configuration and apply this new update — patching one NetScaler CVE no longer implies the appliance is current against the others.

Exposure Scale

Internet-scanning service Shadowserver tracks more than 21,000 IP addresses with NetScaler fingerprints exposed on the public internet — including roughly 1,500 Gateway instances and nearly 20,000 ADC appliances. Shadowserver's figures don't distinguish honeypots, already-patched devices, or safe configurations from genuinely exploitable ones, but the raw exposure count underscores how large the attack surface remains for any new NetScaler flaw.

Recommendations

  1. Check your SAML configuration first — if your NetScaler ADC or Gateway is not configured as a SAML IdP or SP, this specific CVE does not apply, but verify that assumption rather than assuming it.
  2. Upgrade to a fixed build — 14.1-73.46+ or 13.1-64.29+ as appropriate for your branch.
  3. Don't treat this fall's earlier NetScaler patches as sufficient — CVE-2026-88771, -88772, -88779, and -107406 are four distinct issues; confirm your appliance is current against all of them.
  4. Monitor Shadowserver and CISA KEV updates — given the active-exploitation history of this product line in 2026, treat any future NetScaler advisory as high priority by default.

Sources