Yet Another Critical Patch Cycle for NetScaler
Citrix has issued an urgent warning to administrators to patch NetScaler ADC and NetScaler Gateway appliances against a new critical vulnerability, tracked as CVE-2026-107406, published in bulletin CTX697191 on October 8, 2026. The flaw is a memory-overflow weakness (CWE-119) that can let an attacker achieve remote code execution or crash the appliance into a denial-of-service state. It carries a CVSS v4.0 score of 9.5.
To be vulnerable, an appliance must be configured as a SAML Identity Provider (IdP) or Service Provider (SP) — a common setup for organizations using NetScaler to broker single sign-on for internal or customer-facing applications.
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-107406 |
| CVSS v4.0 Score | 9.5 |
| Weakness | CWE-119 — Improper Restriction of Operations within a Memory Buffer |
| Required Configuration | NetScaler ADC/Gateway configured as SAML IdP or SP |
| Bulletin | CTX697191 (published October 8, 2026) |
| Attack Vector | Network, no privileges or user interaction required, high attack complexity |
| Known Exploitation | None confirmed as of publication |
| Credit | Michael Tucker, Chew Keong Tan, Alex Bernier (JPMorgan Chase XOR Team), Maxim Suhanov |
Affected and Fixed Versions
- Affected (IdP only), 14.1: 14.1-73.37 through 14.1-73.41
- Affected (IdP only), 13.1: 13.1-64.23 through 13.1-64.28
- Affected (SP or IdP), 14.1: before 14.1-73.37
- Fixed, 14.1: 14.1-73.46 and later
- Fixed, 13.1: 13.1-64.29 and later 13.1 releases
Citrix said it is "not aware of any unmitigated exploits of this vulnerability" as of the bulletin's publication, but urged affected customers to "review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible."
A Pattern, Not an Isolated Incident
CVE-2026-107406 is the latest in a string of serious NetScaler vulnerabilities disclosed throughout 2026, and the third in roughly two weeks. Three other flaws — CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 — have already come under active exploitation in the wild this fall. CVE-2026-88771 was an unauthenticated RCE caused by improper input validation affecting all NetScaler ADC and Gateway deployments, including default configurations, while CVE-2026-88779 was a SAML-specific zero-day exploited in targeted attacks before Citrix shipped a fix.
That means administrators who already patched for this fall's earlier zero-days still need to separately verify their SAML configuration and apply this new update — patching one NetScaler CVE no longer implies the appliance is current against the others.
Exposure Scale
Internet-scanning service Shadowserver tracks more than 21,000 IP addresses with NetScaler fingerprints exposed on the public internet — including roughly 1,500 Gateway instances and nearly 20,000 ADC appliances. Shadowserver's figures don't distinguish honeypots, already-patched devices, or safe configurations from genuinely exploitable ones, but the raw exposure count underscores how large the attack surface remains for any new NetScaler flaw.
Recommendations
- Check your SAML configuration first — if your NetScaler ADC or Gateway is not configured as a SAML IdP or SP, this specific CVE does not apply, but verify that assumption rather than assuming it.
- Upgrade to a fixed build — 14.1-73.46+ or 13.1-64.29+ as appropriate for your branch.
- Don't treat this fall's earlier NetScaler patches as sufficient — CVE-2026-88771, -88772, -88779, and -107406 are four distinct issues; confirm your appliance is current against all of them.
- Monitor Shadowserver and CISA KEV updates — given the active-exploitation history of this product line in 2026, treat any future NetScaler advisory as high priority by default.
Sources
- Citrix warns admins to patch new NetScaler RCE flaw immediately — BleepingComputer
- CVE-2026-107406: Critical NetScaler SAML RCE Bug Requires ADC and Gateway Upgrades — WindowsForum