Citrix has patched CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway scored CVSS 9.5. On a vulnerable SAML deployment it can lead to remote code execution or a denial of service.
What happened
Citrix published bulletin CTX697191 on 8 October 2026. At publication the company said it was not aware of any unmitigated exploit. That is not a reason to wait. Other NetScaler flaws this year, including CVE-2026-88771 and CVE-2026-88772, moved from patch to active intrusion quickly.
Shadowserver is tracking more than 21,000 internet addresses with a NetScaler fingerprint, including about 1,500 Gateway instances and nearly 20,000 ADC appliances. That figure is not a count of vulnerable hosts. It does show how wide the exposed population is.
Who is affected
Customer-managed NetScaler ADC and NetScaler Gateway are in scope when SAML is configured. Secure Private Access Hybrid deployments that use those NetScaler instances are in scope too.
- Builds from 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, are affected when the appliance is a SAML identity provider. Matching FIPS builds in those ranges follow the same rule.
- Builds before 14.1-73.37 or 13.1-64.23 are affected as either a SAML service provider or a SAML identity provider.
- Look for add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider) in the running config.
What to do now
Upgrade every affected NetScaler to a fixed build today, then confirm the SAML virtual servers came back on the new version.
- 14.1 branch: 14.1-73.46 or later. FIPS: 14.1-73.46 FIPS or later.
- 13.1 branch: 13.1-64.29 or later. 13.1-FIPS and 13.1-NDcPP: 13.1.37.283 or later.
- If you cannot patch this week, remove the appliance from the internet. A SAML remote-access gateway is not a system to leave exposed while you wait for exploit reports.
Source: BleepingComputer, Citrix warns admins to patch new NetScaler RCE flaw immediately. Vendor bulletin: CTX697191.
Also on the blog
- AhsayCBS CVE-2026-105134: SYSTEM RCE, 5 organizations hit
- CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.