
Key takeaways
- CVE-2026-107406 is a memory overflow in NetScaler ADC and Gateway, rated 9.5 on the 10-point CVSS scale, that can lead to remote code execution or denial of service.
- An appliance is only vulnerable if it is configured as a SAML identity provider or a SAML service provider.
- Fixed builds start at 14.1-73.46 and 13.1-64.29, with separate fixed releases for the FIPS and NDcPP variants.
- As of the bulletin, Citrix says it knows of no unmitigated exploits, but it urges customers to upgrade as soon as possible.
Citrix has patched CVE-2026-107406, a critical memory overflow in NetScaler ADC and NetScaler Gateway. Depending on configuration, it can allow remote code execution (RCE) or a denial of service (DoS). The flaw is rated 9.5 on the 10-point CVSS scale, according to The Hacker News and SecurityWeek.
The good news for some admins: it only applies to appliances set up for SAML. Check the config first, then the build number, then pick the upgrade target.
Step 1: Is the appliance configured for SAML?
An appliance is vulnerable only if it acts as a SAML identity provider (IdP) or a SAML service provider (SP). According to The Hacker News, you can tell by searching the configuration for two strings: add authentication samlAction (SAML SP) or add authentication samlIdPProfile (SAML IdP).
If neither string appears, the flaw as described doesn’t apply to that appliance. If either does, move to step 2.
One more case to catch. Hybrid deployments of Secure Private Access that rely on NetScaler instances are affected as well, and those instances need the upgrade too, per The Hacker News and SecurityWeek. If you run that setup, put those instances in your inventory even if you never touched SAML settings on them directly.
Step 2: Does your build fall in an affected range?
A build is in scope if it’s older than 14.1-73.37 or 13.1-64.23 and uses SAML in either role, or if it sits in the narrow bands just below the fixes and acts as an IdP. The Hacker News is the only outlet that published the full version tables, so check Citrix’s own bulletin before you act on a borderline build.
Affected if the appliance is a SAML IdP:
- ADC and Gateway 14.1-73.37 through 14.1-73.41
- 14.1-FIPS 14.1-73.37 FIPS through 14.1-73.41 FIPS
- ADC and Gateway 13.1-64.23 through 13.1-64.28
- FIPS and NDcPP builds of 13.1, from 13.1-37.279 through 13.1-37.282
Affected with SAML in either role (SP or IdP):
- ADC and Gateway before 14.1-73.37
- 14.1-FIPS before 14.1-73.37 FIPS
- ADC and Gateway before 13.1-64.23
- FIPS and NDcPP builds of 13.1 older than 13.1-37.279
In practice the second list covers anything older than the first. If you run an old 13.1 or 14.1 build with SAML in any role, you’re in scope, and the same goes for newer builds acting as an IdP.
Step 3: Which version do you upgrade to?
On the 14.1 branch, move to 14.1-73.46 or later. On 13.1, move to 13.1-64.29 or later. FIPS and NDcPP builds have their own targets, listed below. The fixed releases are reported by The Hacker News, SecurityWeek and BleepingComputer.
- ADC and Gateway: 14.1-73.46 or newer
- ADC and Gateway: 13.1-64.29 or newer in the 13.1 line
- 14.1-FIPS: 14.1-73.46 FIPS or newer
- FIPS and NDcPP builds on the 13.1 line: 13.1.37.283 or newer
Watch the formatting on that last line. The fixed FIPS/NDcPP version is written with dots (13.1.37.283) while the affected ranges use a hyphen (13.1-37.279). That’s probably just notation, but confirm the exact string on Citrix’s bulletin before you download.

Is anyone exploiting CVE-2026-107406 yet?
Citrix says it isn’t aware of any “unmitigated exploits” as of the bulletin’s publication. The Hacker News says there’s no evidence of exploitation in the wild, and BleepingComputer says Citrix hasn’t found any. Treat that as a snapshot, not a guarantee. The word “unmitigated” is Citrix’s, and the company hasn’t said what it covers.
The context is what makes admins nervous. CVE-2026-88771 (RCE) and CVE-2026-88772 (RCE or DoS) were zero-days exploited in attacks and patched in September. SecurityWeek says the victims included government bodies, financial firms, schools and universities, and legal and professional services companies. BleepingComputer reports that attackers deployed custom web shells and tunneling malware, stole credentials, gained root access and moved into victims’ internal networks.
Then came CVE-2026-88779, a NetScaler DoS zero-day with emergency updates earlier in October. The Hacker News counts it among three flaws under active exploitation. SecurityWeek calls it a zero-day but doesn’t say outright that it’s exploited, so the sources differ slightly there. BleepingComputer adds that unnamed researchers and admins later said 88779 could also be abused for RCE. SecurityWeek describes it as DoS-only, and I haven’t seen Citrix confirm the RCE claim.
Why it matters for you
If you run NetScaler as a SAML IdP or SP, this is a this-week patch, not a next-maintenance-window patch. Citrix itself urges customers to upgrade as soon as possible. A 9.5 score on an internet-facing appliance that handles authentication is the kind of bug attackers tend to like.
The exposed footprint is large. Shadowserver counts over 21,000 NetScaler-fingerprinted IP addresses on the internet: nearly 20,000 ADC appliances and just over 1,500 Gateway instances, per BleepingComputer. Those numbers count fingerprints only. BleepingComputer notes there’s no data on how many are honeypots, already patched or running a vulnerable SAML configuration, so don’t read 21,000 as 21,000 vulnerable boxes.
The history adds pressure. Since November 2021, CISA’s count of Citrix vulnerabilities exploited in the wild has reached 27, seven of them used in ransomware attacks, according to BleepingComputer. Citrix also pushed customers to patch two other NetScaler issues, CVE-2026-3055 and CVE-2026-4368, back in March.
My suggestion for the work order: inventory every NetScaler, including those behind Secure Private Access Hybrid. Search each config for the two SAML strings. Compare builds to the tables above. Upgrade the matches first. Check the build number even on appliances you updated recently, because the October emergency updates were for a different CVE.
If you manage authentication more broadly, our piece on agent identities and IT questions covers a different identity headache. For a wider view of how admins should think about attacker behavior, see our threat model for admins.
What we don’t know yet
Several things are unanswered. Citrix hasn’t said, in anything reported so far, whether there are workarounds for admins who can’t upgrade right away. Nobody has said whether proof-of-concept code exists or when exploitation might start, though earlier NetScaler flaws were attacked quickly.
It’s also unclear how many of those 21,000 exposed addresses are actually set up as SAML IdP or SP. And it’s not known whether the recent NetScaler flaws are linked or exploited by the same actors. Nor has it been reported whether the Secure Private Access Hybrid exposure goes beyond NetScaler instances.
The Hacker News credits Maxim Suhanov and three members of JPMorgan Chase’s XOR Team, Alex Bernier, Chew Keong Tan and Michael Tucker, with finding CVE-2026-107406. The exact publication date is also worth confirming. SecurityWeek says Thursday, and The Register’s URL is dated 2026-10-09.
Frequently asked questions
What is CVE-2026-107406?
It's a critical memory overflow in NetScaler ADC and NetScaler Gateway, scored 9.5 out of 10.0. It can lead to remote code execution or denial of service, depending on configuration, on appliances set up for SAML.
How do I check if my NetScaler is configured as a SAML IdP or SP?
According to The Hacker News, look in the configuration for 'add authentication samlAction' (SAML SP) or 'add authentication samlIdPProfile' (SAML IdP). Either string means the appliance is configured for SAML.
Is CVE-2026-107406 being exploited in the wild?
Citrix says that as of the bulletin it knows of no unmitigated exploits. The Hacker News reports no evidence of exploitation, and BleepingComputer says Citrix hasn't found any.
What NetScaler version fixes CVE-2026-107406?
Fixed builds are ADC and Gateway 14.1-73.46 and later, and 13.1-64.29 and later 13.1 releases. FIPS builds need 14.1-73.46 FIPS or later, while the 13.1 FIPS and NDcPP builds need 13.1.37.283 or later.
Get the next one in your inbox. One email a day with the tech stories that matter, explained in plain English. Subscribe free.
Sources
This article was compiled from reporting by the following outlets. Links go to the original reports.
- The Hacker News: Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
- SecurityWeek: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- BleepingComputer: Citrix warns admins to patch new NetScaler RCE flaw immediately
- The Register: Citrix gives NetScaler admins another critical reason to patch
