Skip to content
← All SecurityAlert research
Research Analysis Critical priority

CVE-2026-107406: Citrix fixes critical NetScaler SAML memory overflow

A new NetScaler vulnerability can allow remote code execution or denial of service. Check the SAML role and running build: some recently patched IdP deployments need another update.

Share:
At a glance

What happened

Citrix disclosed CVE-2026-107406 on October 8 with a Critical CVSS v4.0 score of 9.5. Affected SAML roles vary by build, and new fixes are available for four release families. Citrix said it was not aware of any unmitigated exploits at publication.

Impact

NetScaler builds 14.1-73.41 and 13.1-64.28 fixed CVE-2026-88779, but Citrix lists them as affected by this separate flaw when configured as a SAML identity provider (IdP). The potential impact includes remote code execution and service disruption.

Those deployments need another update: 14.1-73.46 for the 14.1 branch, or 13.1-64.29 for 13.1. Older releases can also be affected in SAML service provider (SP) configurations. Check each node against the full affected ranges and fixed releases below, including the separate FIPS and NDcPP builds.

Citrix releases new NetScaler fixes

Citrix has disclosed CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can cause remote code execution or denial of service. Its October 8 bulletin rates the vulnerability Critical, CVSS v4.0 9.5.

The immediate task is to check both the running build and the appliance's SAML role. Some recently patched appliances remain affected when configured as a SAML identity provider. Older builds can also be affected when operating as a SAML service provider.

The SecurityAlert CVE record includes the release comparison and response guidance. This article is based on Citrix bulletin CTX697191 and Citrix's October 8 explanation, reviewed October 8, 2026.

Exploitation status at publication

Citrix says that, when it published the bulletin, it was not aware of any unmitigated exploits of this vulnerability. That statement is limited to the vendor's knowledge at publication. It does not establish whether a particular appliance has been compromised.

The two publications reviewed here do not provide indicators of compromise or a public exploit. We are not attributing the malware, addresses or crashes described in earlier NetScaler reporting to this CVE.

Our earlier SAML investigation covers CVE-2026-88779 and the surrounding activity. Its exploitation findings should not be transferred to CVE-2026-107406 without evidence identifying this vulnerability.

Which configurations are affected

For the following recent builds, Citrix lists SAML IdP as the affected configuration. Each range includes both endpoints:

  • ADC and Gateway 14.1: 14.1-73.37 through 14.1-73.41.
  • ADC and Gateway 13.1: 13.1-64.23 through 13.1-64.28.
  • ADC 14.1 FIPS: 14.1-73.37 FIPS through 14.1-73.41 FIPS.
  • ADC 13.1 FIPS / NDcPP: Citrix's grouped entry specifies 13.1-37.279 through 13.1-37.282. Confirm the edition against CTX697191.

For builds earlier than the lower endpoints above, Citrix lists either SAML SP or SAML IdP as the affected configuration. Do not apply the IdP-only condition to those older builds.

The bulletin covers customer-managed appliances, including applicable NetScaler instances in Secure Private Access Hybrid deployments. Citrix handles updates for its managed cloud services and Adaptive Authentication.

Identify the SAML role

Citrix identifies these entries to look for in the existing configuration:

  • SAML service provider: add authentication samlAction
  • SAML identity provider: add authentication samlIdPProfile

These are configuration search patterns, not instructions to add authentication objects. Record the matching configuration and the running software build on each node, then compare them with the affected ranges. A version number alone is insufficient to apply the bulletin accurately.

Fixed releases

Citrix recommends installing the appropriate update as soon as possible:

  • ADC and Gateway 14.1: 14.1-73.46 or a later fixed release in the branch.
  • ADC and Gateway 13.1: 13.1-64.29 or a later fixed release in the branch.
  • ADC 14.1 FIPS: 14.1-73.46 FIPS or a later fixed release in that edition.
  • ADC 13.1 FIPS / NDcPP: 13.1.37.283 or a later fixed release in that edition, using the build notation printed in CTX697191.

The previously recommended 14.1-73.41 and 13.1-64.28 fixes for CVE-2026-88779 fall within this bulletin's affected IdP ranges. Completing that earlier change does not close this new issue for those deployments.

The reviewed publications direct affected operators to upgrade. They do not establish that the Global Deny List settings discussed for the earlier SAML vulnerability mitigate CVE-2026-107406.

Verify the change and investigate suspicious activity

SecurityAlert recommends recording the installed build on every node after upgrading, including the standby appliance, then testing SAML sign-in and failover through the normal change process. Keep the configuration and version evidence with the change record.

If an appliance has unexplained authentication failures, restarts, processes or outbound connections, preserve available logs and other evidence and involve incident response and Citrix Support. Those observations need investigation; they do not identify this CVE as their cause. Installing the update addresses the vulnerability but does not establish that earlier unauthorized access never occurred.

What to do

What teams should do now

  1. Inventory the running build, release branch and SAML role on every ADC and Gateway node, including standby nodes and applicable Secure Private Access Hybrid instances.
  2. Look for existing add authentication samlAction entries for SAML SP and add authentication samlIdPProfile entries for SAML IdP. These are configuration search patterns, not commands to run.
  3. Upgrade affected deployments to the matching CTX697191 fixed build: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1.37.283 for 13.1 FIPS / NDcPP, as printed by Citrix.
  4. Verify the running build, SAML sign-in and failover after the update. Preserve and investigate suspicious authentication, crash or process activity separately from patch completion.
Sources

Research behind this article

We based this article on the research below.

  1. CTX697191: NetScaler security bulletin for CVE-2026-107406 Citrix | Oct 8, 2026
  2. Immediate guidance for CVE-2026-107406 Citrix / NetScaler Cyber Threat Intelligence | Oct 8, 2026