Skip to content

Citrix patches critical NetScaler SAML flaw CVE-2026-107406

Citrix patched CVE-2026-107406, a CVSS 9.5 memory-overflow flaw in NetScaler ADC and Gateway SAML deployments that can lead to RCE or DoS. No exploitation reported yet.

Published 2 min read

Citrix has patched CVE-2026-107406, a memory-overflow flaw in NetScaler ADC and NetScaler Gateway that the vendor scores 9.5 and describes as a condition that "may lead to remote code execution or denial-of-service under specific configuration conditions." The fix is in Citrix advisory CTX697191. There is no evidence of exploitation in the wild.

What's affected

The flaw is only reachable when the appliance is configured for SAML — as an identity provider (authentication samlIdPProfile) or, for the pre-fix range, as a service provider (authentication samlAction). Appliances with no SAML configuration are not in scope.

Affected versions, per Citrix:

  • NetScaler ADC and Gateway 14.1 before 14.1-73.46 (the 14.1-73.37 → 14.1-73.41 range is affected when configured as a SAML IdP)
  • NetScaler ADC and Gateway 13.1 before 13.1-64.29
  • NetScaler ADC 14.1-FIPS before 14.1-73.46 FIPS
  • NetScaler ADC 13.1-FIPS / 13.1-NDcPP before 13.1-37.283

Versions 12.1 and 13.0 are end-of-life and receive no fix; Citrix tells operators on those branches to migrate to a supported build.

Exploitation status

Citrix reports no in-the-wild exploitation of CVE-2026-107406. That is the one piece of good news here: separate NetScaler flaws disclosed recently — among them CVE-2026-88771 and CVE-2026-88779 — are under active exploitation, and operators have learned the hard way that NetScaler bugs get weaponised fast once a build diff is public.

Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, along with independent researcher Maxim Suhanov.

Action checklist

  1. Identify whether any NetScaler ADC or Gateway instance uses SAML. On the CLI, check for authentication samlIdPProfile or authentication samlAction bindings.
  2. Upgrade affected instances to 14.1-73.46, 13.1-64.29, or the matching FIPS/NDcPP build — or later — per CTX697191.
  3. If you run 12.1 or 13.0, there is no patch. Migrate to a supported branch now.
  4. After upgrading, review authentication logs for malformed SAML requests, and rotate any secrets that touched an exposed appliance if you cannot rule out pre-patch access.

Context

This is the fourth NetScaler advisory this site has covered in short order, and the pattern is familiar: a gateway appliance sitting on the network edge, a SAML code path, and a build that attackers can diff. CVE-2026-107406 is not yet exploited, but "not yet" has a short half-life on this product. The appliances exposed to CVE-2026-88779 were being hit within days of disclosure. Treat the window between patch availability and mass scanning as the time you have, not the time you'd like.

Related stories