Citrix published bulletin CTX697191 on 8 October 2026 for CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway. The flaw can lead to remote code execution or denial of service. Citrix rates it critical, CVSS v4.0 9.5, and said it was not aware of unmitigated exploits at publication. Australian Cyber Security Centre noted on 9 October that earlier patches do not fix this issue.
What happened
The bug is a failure to keep operations inside a memory buffer (CWE-119). It only matters when the appliance is a SAML identity provider or SAML service provider, and the exact condition depends on the build. On a narrow set of recent builds it applies only when the box is a SAML IdP. On older builds it applies to both IdP and SP.
Citrix says to look for add authentication samlAction (SAML SP) or add authentication samlIdPProfile (SAML IdP). Secure Private Access Hybrid deployments that use NetScaler are in scope too. JPMorgan Chase XOR Team researchers and Maxim Suhanov are credited with the report.
Who is affected
Supported NetScaler ADC and Gateway builds that match the SAML precondition. Fixed releases are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-73.46 FIPS and later, and 13.1-FIPS / NDcPP 13.1-37.283 and later.
- Builds 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, only when configured as a SAML IdP.
- Builds before 14.1-73.37 and before 13.1-64.23 when configured as a SAML SP or SAML IdP.
- Matching FIPS and NDcPP builds in those same ranges.
What to do now
If the appliance is a SAML IdP or SP, upgrade to 14.1-73.46 or 13.1-64.29 (or the matching FIPS build) and do not treat last week's NetScaler patches as enough. Confirm the running build after the upgrade. Three other NetScaler flaws, CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779, are already exploited in the wild, so a SAML gateway that is behind on any of those should be treated as a possible intrusion, not only a missing patch.
Source: Citrix security bulletin CTX697191, CVE-2026-107406.
Also on the blog
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- ARTEX AI pentest agent used in South Korean bank data theft
- Cisco NX-OS CVE-2026-76471 and four more flaws score 9.8
- Japan web data leaks hit 119 in 2026, 81 since July
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.