Citrix NetScaler ADC and Gateway: SAML-path memory overflow leading to code execution or denial of service, affecting identity-provider appliances on the 2026-10-03 fixed builds (CVSS 4.0 9.5)
cve · CVE-2026-107406 single-source
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-107406, newest first. Check the date before acting on an older one.
- Upgrade each SAML identity-provider NetScaler (2026-10-09CVE-2026-107406
add authentication samlIdPProfile) straight to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1.37.283 (13.1-FIPS and NDcPP), including appliances already on 14.1-73.41 or 13.1-64.28; a service-provider-only appliance (add authentication samlAction) below 14.1-73.37 or 13.1-64.23 (FIPS and NDcPP: 13.1-37.279) needs the same builds.
Defender insights
What each entry about CVE-2026-107406 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-09/cve-2026-107406-citrix-netscaler-saml-idp-overflow · ATT&CK page ↗
Entries about Citrix NetScaler ADC and Gateway: SAML-path memory overflow leading to code execution or denial of service, affecting identity-provider appliances on the 2026-10-03 fixed builds (CVSS 4.0 9.5) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- support.citrix.com2 (50%)
- community.citrix.com1 (25%)
- cyber.gov.au1 (25%)
External references
All cited sources (4)
- support.citrix.comprimaryCitrix (Cloud Software Group)https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html
- support.citrix.comprimaryCitrix (Cloud Software Group)https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html
- community.citrix.comCitrix (Cloud Software Group)https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
- cyber.gov.auASD's ACSChttps://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products