CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)
Citrix: a new NetScaler SAML overflow, rated Critical, reaches the builds that fixed the previous one
Defender actions
- Upgrade each SAML identity-provider NetScaler (
add authentication samlIdPProfile) straight to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1.37.283 (13.1-FIPS and NDcPP), including appliances already on 14.1-73.41 or 13.1-64.28; a service-provider-only appliance (add authentication samlAction) below 14.1-73.37 or 13.1-64.23 (FIPS and NDcPP: 13.1-37.279) needs the same builds.
Analysis
Citrix's bulletin CTX697191 describes CVE-2026-107406 as a memory overflow (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway that leads to remote code execution or denial of service; the CVSS 4.0 vector is network, high attack complexity, no privileges, no user interaction, base score 9.5, and Citrix rates the bulletin Critical (Citrix, 2026-10-08). The precondition is a SAML configuration: the appliance must be a SAML service provider or a SAML identity provider (Citrix, 2026-10-08). An appliance configured as a service provider is listed as affected before 14.1-73.37 and 13.1-64.23 (ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.279), and the identity-provider case reaches further: 14.1-73.37 through 14.1-73.41, 13.1-64.23 through 13.1-64.28 and the matching FIPS and NDcPP builds through 14.1-73.41 FIPS and 13.1-37.282 are affected "only when configured as a SAML IdP" (Citrix, 2026-10-08). Those are the builds that Citrix's earlier bulletin CTX697174 named as the fix for CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 (Citrix, 2026-10-03), so an identity-provider appliance that followed that guidance is exposed again.
Citrix urges customers to install 14.1-73.46 and later, 13.1-64.29 and later of 13.1, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later (Citrix, 2026-10-08). Secure Private Access Hybrid deployments that use NetScaler instances are also affected, while Citrix upgrades its own cloud services and managed Adaptive Authentication (Citrix, 2026-10-08). The bulletin states no exploitation status, publishes no workaround and gives no indicators of compromise; Citrix's blog of the same day says that as of the bulletin's publication it is not aware of any unmitigated exploits (Citrix, 2026-10-08), and no independent report of exploitation had surfaced as of 2026-10-09. ASD's ACSC added the flaw to its Citrix alert on 2026-10-09, saying the previous patches are insufficient for it and urging the latest patches (ASD's ACSC, 2026-10-09).
Cited evidence
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP
Applicable only when configured as a SAML IdP
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix is not aware of any unmitigated exploits of this vulnerability.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.