A cybersecurity dashboard shows a server vulnerability fixed by a software update, linking SAML identity and service providers.
Citrix has published a critical NetScaler advisory, and this one depends on how the appliance is configured. Bulletin CTX697191 was published on the evening of 8 October, European time. It covers CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service, with a CVSS v4.0 score of 9.5. If you run NetScaler as a front door for remote access or application delivery, check this one today.

A cybersecurity dashboard shows a server vulnerability fixed by a software update, linking SAML identity and service providers. What the flaw is​

The bulletin classifies the bug as CWE-119, improper restriction of operations within the bounds of a memory buffer. The CVSS v4.0 vector is AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L. In plain terms:

  • It can be reached over the network.
  • Attack complexity is high.
  • It needs no privileges and no user interaction.
  • The impact on confidentiality, integrity and availability is high.

The high attack complexity is probably why this scores 9.5 rather than 10. That doesn't make it comfortable. This is memory corruption on a perimeter device.

Who is actually exposed​

Not every NetScaler is vulnerable. The appliance must be configured as a SAML service provider (SP) or SAML identity provider (IdP), and the version decides which role matters. Citrix splits the affected builds into two groups.

Vulnerable only as a SAML IdP:

  • ADC and Gateway 14.1-73.37 through 14.1-73.41
  • ADC 14.1-FIPS 14.1-73.37 FIPS through 14.1-73.41 FIPS
  • ADC and Gateway 13.1-64.23 through 13.1-64.28
  • ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 through 13.1-37.282

Vulnerable as either a SAML SP or a SAML IdP:

  • ADC and Gateway before 14.1-73.37
  • ADC 14.1-FIPS before 14.1-73.37 FIPS
  • ADC and Gateway before 13.1-64.23
  • ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279

Two more scope points from Citrix:

  • Secure Private Access Hybrid deployments that use NetScaler instances are also affected. Those instances need the same upgrade.
  • The bulletin applies only to customer-managed ADC and Gateway. Citrix says it upgrades its own cloud services and Citrix-managed Adaptive Authentication.

Don't shorten this to "SAML means vulnerable." Builds from the middle range are exposed only if they act as an IdP.

Check your configuration​

Citrix says to search the appliance configuration for these entries:

  • SAML SP: add authentication samlAction
  • SAML IdP: add authentication samlIdPProfile

Match what you find against your build number and the lists above. Having the string doesn't make you vulnerable on its own. Your version decides whether the SP role counts.

The fixed builds​

Citrix urges affected customers to install these releases or later:

ProductFixed release
NetScaler ADC and Gateway14.1-73.46 and later
NetScaler ADC and Gateway13.1-64.29 and later 13.1 releases
NetScaler ADC 14.1-FIPS14.1-73.46 FIPS and later
NetScaler ADC 13.1-FIPS and 13.1-NDcPP13.1.37.283 and later

Check the FIPS and NDcPP numbering carefully. Those tracks use their own build numbers and are not ordinary 13.1 builds.

One third-party write-up says the bulletin lists no workaround. The practical path is to upgrade.

Exploitation status​

BleepingComputer quotes Citrix saying that, when the bulletin was published, it knew of no unmitigated exploits of this flaw. Treat that as a snapshot from 8 October, not a standing guarantee. The vendor's statement shouldn't make anyone relax.

BleepingComputer also reports that Citrix urged customers to patch two NetScaler flaws in March, days before attackers began abusing them. It says September brought updates for actively exploited NetScaler RCE zero-days, followed by an emergency fix for a denial-of-service zero-day that researchers later said could also give RCE. I haven't independently verified those earlier cases. They are BleepingComputer's account, and they show a pattern, not evidence about this CVE.

BleepingComputer also cites Shadowserver tracking over 21,000 Internet-exposed IP addresses with NetScaler fingerprints. That is nearly 20,000 ADC appliances and just over 1,500 Gateway instances. The report itself says it's unclear how many are honeypots, already patched, or configured in a vulnerable way. That figure shows how big the NetScaler footprint is. It doesn't show how many appliances are vulnerable.

What admins should do now​

  1. Inventory every NetScaler ADC and Gateway, including Secure Private Access Hybrid back ends.
  2. Record each build number, including FIPS and NDcPP variants.
  3. Search each configuration for the two SAML strings above.
  4. Compare the results to the version tables to decide who is exposed.
  5. Schedule upgrades to the fixed builds, with the SAML-configured appliances first.
  6. Plan for the chance that someone gets there before you. In reporting summarised by Poppelgaard, Kevin Beaumont said compromised appliances showed a different shell on each device. Hunting for one file name or hash won't be enough. That account concerns earlier NetScaler intrusions, not confirmed attacks on this CVE.

NetScaler Console workflow​

NetScaler's Console documentation describes a way to find affected instances in bulk. I couldn't retrieve that page directly, so this comes from the research notes on it:

  1. In NetScaler Console, open Security Advisory > CVE Detection.
  2. On Impacted Instances, search for CVE-2026-107406.
  3. Select the affected instances and choose Proceed to upgrade workflow.
  4. Upgrade to a release that contains the fix.

The notes say the advisory scan can take a couple of hours and that Scan-Now starts an on-demand scan. Console is a convenience for fleet management. It doesn't replace checking the target build and your SAML configuration yourself.

Bottom line​

This is a critical, network-reachable memory flaw on identity-aware perimeter devices. It's patchable, and the exposure is narrower than "every NetScaler." That makes the sensible plan simple: identify the SAML-configured appliances, confirm their builds, and move them to the fixed releases before someone else does the homework for you. Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, for reporting the issue.

 

References

  1. Citrix warns admins to patch new NetScaler RCE flaw immediately BleepingComputer 2026-10-09T04:27:42-04:00
  2. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406 support.citrix.com
  3. CVE-2026-88771 through CVE-2026-88778, CVE-2026-88779 and CVE-2026-107406, what you should know and how to fix your NetScaler ADC, NetScaler Gateway - Poppelgaard.com poppelgaard.com