CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Citrix NetScaler ADC and Gateway: SAML-path memory overflow leading to code execution or denial of service, affecting identity-provider appliances on the 2026-10-03 fixed builds (CVSS 4.0 9.5)

cve · CVE-2026-107406 single-source

Coverage
1
first 2026-10-09 → last 2026-10-09
Latest activity
2026-10-09
Citrix: a new NetScaler SAML overflow, rated Critical, reaches the builds that fixed the previous one
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
4
3 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-107406, newest first. Check the date before acting on an older one.

  • Upgrade each SAML identity-provider NetScaler (add authentication samlIdPProfile) straight to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1.37.283 (13.1-FIPS and NDcPP), including appliances already on 14.1-73.41 or 13.1-64.28; a service-provider-only appliance (add authentication samlAction) below 14.1-73.37 or 13.1-64.23 (FIPS and NDcPP: 13.1-37.279) needs the same builds.
    2026-10-09CVE-2026-107406

Defender insights

What each entry about CVE-2026-107406 tells a defender to do, newest first.

2026-10-09NOTABLECitrix: a new NetScaler SAML overflow, rated Critical, reaches the builds that fixed the previous one

Exposure · detection

Story timeline

  1. 2026-10-09CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)
    trending-vulnerabilitiesCitrix: a new NetScaler SAML overflow, rated Critical, reaches the builds that fixed the previous one
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-09/cve-2026-107406-citrix-netscaler-saml-idp-overflow · ATT&CK page ↗

Entries about Citrix NetScaler ADC and Gateway: SAML-path memory overflow leading to code execution or denial of service, affecting identity-provider appliances on the 2026-10-03 fixed builds (CVSS 4.0 9.5) (1)

2026-10-09 · view entry permalink →

NOTABLECVE-2026-107406NATOA2

CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)

Citrix's bulletin CTX697191 describes CVE-2026-107406 as a memory overflow (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway that leads to remote code execution or denial of service; the CVSS 4.0 vector is network, high attack complexity, no privileges, no user interaction, base score 9.5, and Citrix rates the bulletin Critical (Citrix, 2026-10-08). The precondition is a SAML configuration: the appliance must be a SAML service provider or a SAML identity provider (Citrix, 2026-10-08). An appliance configured as a service provider is listed as affected before 14.1-73.37 and 13.1-64.23 (ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.279), and the identity-provider case reaches further: 14.1-73.37 through 14.1-73.41, 13.1-64.23 through 13.1-64.28 and the matching FIPS and NDcPP builds through 14.1-73.41 FIPS and 13.1-37.282 are affected "only when configured as a SAML IdP" (Citrix, 2026-10-08). Those are the builds that Citrix's earlier bulletin CTX697174 named as the fix for CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03), so an identity-provider appliance that followed that guidance is exposed again.

Citrix urges customers to install 14.1-73.46 and later, 13.1-64.29 and later of 13.1, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later (Citrix, 2026-10-08). Secure Private Access Hybrid deployments that use NetScaler instances are also affected, while Citrix upgrades its own cloud services and managed Adaptive Authentication (Citrix, 2026-10-08). The bulletin states no exploitation status, publishes no workaround and gives no indicators of compromise; Citrix's blog of the same day says that as of the bulletin's publication it is not aware of any unmitigated exploits (Citrix, 2026-10-08), and no independent report of exploitation had surfaced as of 2026-10-09. ASD's ACSC added the flaw to its Citrix alert on 2026-10-09, saying the previous patches are insufficient for it and urging the latest patches (ASD's ACSC, 2026-10-09).

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP

Applicable only when configured as a SAML IdP

Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases

Citrix is not aware of any unmitigated exploits of this vulnerability.

Citrix (Cloud Software Group) 2026-10-08

Builds on: Citrix confirms attacks on a new NetScaler SAML flaw that the September fixed builds do not… · Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days and…

vulnerability09 Oct 03:42Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • support.citrix.com2 (50%)
  • community.citrix.com1 (25%)
  • cyber.gov.au1 (25%)