Citrix NetScaler CVE-2026-107406 scores 9.5 on SAML deployments
NetScaler ADC Gateway SAML memory overflow remote code execution

Citrix NetScaler CVE-2026-107406 scores 9.5 on SAML deployments

Citrix published bulletin CTX697191 on 8 October 2026 for CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway. The flaw can lead to remote code execution or denial of service. Citrix rates it critical, CVSS v4.0 9.5, and said it was not aware of unmitigated exploits at publication. Australian Cyber Security Centre noted on 9 October that earlier patches do not fix this issue.

What happened

The bug is a failure to keep operations inside a memory buffer (CWE-119). It only matters when the appliance is a SAML identity provider or SAML service provider, and the exact condition depends on the build. On a narrow set of recent builds it applies only when the box is a SAML IdP. On older builds it applies to both IdP and SP.

Citrix says to look for add authentication samlAction (SAML SP) or add authentication samlIdPProfile (SAML IdP). Secure Private Access Hybrid deployments that use NetScaler are in scope too. JPMorgan Chase XOR Team researchers and Maxim Suhanov are credited with the report.

Who is affected

Supported NetScaler ADC and Gateway builds that match the SAML precondition. Fixed releases are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-73.46 FIPS and later, and 13.1-FIPS / NDcPP 13.1-37.283 and later.

  • Builds 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, only when configured as a SAML IdP.
  • Builds before 14.1-73.37 and before 13.1-64.23 when configured as a SAML SP or SAML IdP.
  • Matching FIPS and NDcPP builds in those same ranges.

What to do now

If the appliance is a SAML IdP or SP, upgrade to 14.1-73.46 or 13.1-64.29 (or the matching FIPS build) and do not treat last week's NetScaler patches as enough. Confirm the running build after the upgrade. Three other NetScaler flaws, CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779, are already exploited in the wild, so a SAML gateway that is behind on any of those should be treated as a possible intrusion, not only a missing patch.

Source: Citrix security bulletin CTX697191, CVE-2026-107406.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2015-3306 ProFTPD file read added to CISA KEV, due 11 October
mod_copy SITE CPFR and CPTO still exploited on exposed FTP