---
schema: 1
kind: vulnerability
title: "CVE-2026-107406, Citrix NetScaler ADC and Gateway: a SAML-path memory overflow that can lead to code execution still affects the 2026-10-03 fixed builds on identity-provider appliances (CVSS 4.0 9.5)"
headline: "Citrix: a new NetScaler SAML overflow, rated Critical, reaches the builds that fixed the previous one"
summary: >
  Citrix's bulletin CTX697191 (2026-10-08, severity Critical) fixes CVE-2026-107406, a memory overflow in customer-managed
  NetScaler ADC and Gateway that leads to remote code execution or denial of service (CVSS 4.0 9.5) when the appliance is
  configured as a SAML service provider or identity provider. An identity-provider appliance is affected through the
  14.1-73.41 and 13.1-64.28 builds that Citrix named for CVE-2026-88779 and must move to 14.1-73.46, 13.1-64.29 or the FIPS
  builds; Citrix says it is not aware of any unmitigated exploits.
discovered_at: "2026-10-09T03:42:00Z"
updated_at: null
event_date: "2026-10-08"
run_id: 2026-10-09T0255Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, pre-auth, rce, dos, patch-available]
regions: [global]
sectors: []
entities: ["product:citrix-netscaler"]
techniques: [T1190]
affected_products: ["Citrix NetScaler ADC", "Citrix NetScaler Gateway"]
cves:
  - id: CVE-2026-107406
    cvss: "9.5"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "NetScaler ADC and Gateway before 14.1-73.37 and before 13.1-64.23 (ADC 14.1-FIPS before 14.1-73.37 FIPS; ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279) when configured as a SAML service provider or identity provider; as a SAML identity provider only, also 14.1-73.37 through 14.1-73.41, 14.1-FIPS 14.1-73.37 FIPS through 14.1-73.41 FIPS, 13.1-64.23 through 13.1-64.28 and 13.1-FIPS and 13.1-NDcPP 13.1-37.279 through 13.1-37.282"
    fixed: "14.1-73.46 and later; 13.1-64.29 and later; 14.1-FIPS 14.1-73.46 FIPS and later; 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later"
sources:
  - url: "https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-08"
    role: primary
  - url: "https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-03"
    role: corroborating
  - url: "https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/"
    publisher: "Citrix (Cloud Software Group)"
    date: "2026-10-08"
    role: corroborating
  - url: "https://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products"
    publisher: "ASD's ACSC"
    date: "2026-10-09"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html"
  - quote: "NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html"
  - quote: "Applicable only when configured as a SAML IdP"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html"
  - quote: "Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases"
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html"
  - quote: "Citrix is not aware of any unmitigated exploits of this vulnerability."
    publisher: "Citrix (Cloud Software Group)"
    source_url: "https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/"
verification: single-source
sourcing_note: >
  The vendor's own bulletin and blog carry the disclosure and Citrix says it is not aware of any unmitigated exploits; ASD's ACSC
  restates the disclosure in its Citrix alert and adds no independent observation.
confidence: high
references:
  - "2026-10-04/cve-2026-88779-citrix-netscaler-saml-overflow-exploited"
  - "2026-09-28/cve-2026-88771-citrix-netscaler-preauth-rce-zero-day-kev"
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Upgrade each SAML identity-provider NetScaler (`add authentication samlIdPProfile`) straight to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1.37.283 (13.1-FIPS and NDcPP), including appliances already on 14.1-73.41 or 13.1-64.28; a service-provider-only appliance (`add authentication samlAction`) below 14.1-73.37 or 13.1-64.23 (FIPS and NDcPP: 13.1-37.279) needs the same builds."
updates: []
migrated_from: null
---

Citrix's bulletin CTX697191 describes CVE-2026-107406 as a memory overflow (CWE-119) in customer-managed NetScaler ADC and NetScaler Gateway that leads to remote code execution or denial of service; the CVSS 4.0 vector is network, high attack complexity, no privileges, no user interaction, base score 9.5, and Citrix rates the bulletin Critical ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)). The precondition is a SAML configuration: the appliance must be a SAML service provider or a SAML identity provider ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)). An appliance configured as a service provider is listed as affected before 14.1-73.37 and 13.1-64.23 (ADC 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS and 13.1-NDcPP before 13.1-37.279), and the identity-provider case reaches further: 14.1-73.37 through 14.1-73.41, 13.1-64.23 through 13.1-64.28 and the matching FIPS and NDcPP builds through 14.1-73.41 FIPS and 13.1-37.282 are affected "only when configured as a SAML IdP" ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)). Those are the builds that Citrix's earlier bulletin CTX697174 named as the fix for CVE-2026-88779: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 ([Citrix, 2026-10-03](https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html)), so an identity-provider appliance that followed that guidance is exposed again.

Citrix urges customers to install 14.1-73.46 and later, 13.1-64.29 and later of 13.1, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)). Secure Private Access Hybrid deployments that use NetScaler instances are also affected, while Citrix upgrades its own cloud services and managed Adaptive Authentication ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)). The bulletin states no exploitation status, publishes no workaround and gives no indicators of compromise; Citrix's blog of the same day says that as of the bulletin's publication it is not aware of any unmitigated exploits ([Citrix, 2026-10-08](https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/)), and no independent report of exploitation had surfaced as of 2026-10-09. ASD's ACSC added the flaw to its Citrix alert on 2026-10-09, saying the previous patches are insufficient for it and urging the latest patches ([ASD's ACSC, 2026-10-09](https://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products)).

**Exposure:** a customer-managed NetScaler ADC or Gateway whose configuration holds an `add authentication samlAction` entry (service provider) or an `add authentication samlIdPProfile` entry (identity provider); compare the running build with the lists above, and treat an identity provider on 14.1-73.41 or 13.1-64.28 as affected ([Citrix, 2026-10-08](https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html)).

**Detection:** Citrix names no signs of compromise. A denial of service on an authentication appliance would show as restarts or failovers in appliance system and high-availability logs, and the other telemetry to keep is inbound SAML request volume in gateway access logs; none of it shows a patched appliance clean.

**Defender takeaway:** check every SAML-configured appliance now, identity providers first: one that took the 2026-10-03 builds needs a second upgrade to 14.1-73.46, 13.1-64.29 or the FIPS builds. An appliance that is only a service provider is listed as affected only below 14.1-73.37 and 13.1-64.23.
