CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
SAML IdP or SP memory overflow on NetScaler ADC and Gateway

CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5

Citrix has patched CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway scored CVSS 9.5. On a vulnerable SAML deployment it can lead to remote code execution or a denial of service.

What happened

Citrix published bulletin CTX697191 on 8 October 2026. At publication the company said it was not aware of any unmitigated exploit. That is not a reason to wait. Other NetScaler flaws this year, including CVE-2026-88771 and CVE-2026-88772, moved from patch to active intrusion quickly.

Shadowserver is tracking more than 21,000 internet addresses with a NetScaler fingerprint, including about 1,500 Gateway instances and nearly 20,000 ADC appliances. That figure is not a count of vulnerable hosts. It does show how wide the exposed population is.

Who is affected

Customer-managed NetScaler ADC and NetScaler Gateway are in scope when SAML is configured. Secure Private Access Hybrid deployments that use those NetScaler instances are in scope too.

  • Builds from 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, are affected when the appliance is a SAML identity provider. Matching FIPS builds in those ranges follow the same rule.
  • Builds before 14.1-73.37 or 13.1-64.23 are affected as either a SAML service provider or a SAML identity provider.
  • Look for add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider) in the running config.

What to do now

Upgrade every affected NetScaler to a fixed build today, then confirm the SAML virtual servers came back on the new version.

  • 14.1 branch: 14.1-73.46 or later. FIPS: 14.1-73.46 FIPS or later.
  • 13.1 branch: 13.1-64.29 or later. 13.1-FIPS and 13.1-NDcPP: 13.1.37.283 or later.
  • If you cannot patch this week, remove the appliance from the internet. A SAML remote-access gateway is not a system to leave exposed while you wait for exploit reports.

Source: BleepingComputer, Citrix warns admins to patch new NetScaler RCE flaw immediately. Vendor bulletin: CTX697191.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Japan web data leaks hit 119 in 2026, 81 since July
JPCERT mobile API abuse and Metabase CVE-2026-72898