What the flaw is
The bulletin classifies the bug as CWE-119, improper restriction of operations within the bounds of a memory buffer. The CVSS v4.0 vector is AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L. In plain terms:
- It can be reached over the network.
- Attack complexity is high.
- It needs no privileges and no user interaction.
- The impact on confidentiality, integrity and availability is high.
The high attack complexity is probably why this scores 9.5 rather than 10. That doesn't make it comfortable. This is memory corruption on a perimeter device.
Who is actually exposed
Not every NetScaler is vulnerable. The appliance must be configured as a SAML service provider (SP) or SAML identity provider (IdP), and the version decides which role matters. Citrix splits the affected builds into two groups.
Vulnerable only as a SAML IdP:
- ADC and Gateway 14.1-73.37 through 14.1-73.41
- ADC 14.1-FIPS 14.1-73.37 FIPS through 14.1-73.41 FIPS
- ADC and Gateway 13.1-64.23 through 13.1-64.28
- ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 through 13.1-37.282
Vulnerable as either a SAML SP or a SAML IdP:
- ADC and Gateway before 14.1-73.37
- ADC 14.1-FIPS before 14.1-73.37 FIPS
- ADC and Gateway before 13.1-64.23
- ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.279
Two more scope points from Citrix:
- Secure Private Access Hybrid deployments that use NetScaler instances are also affected. Those instances need the same upgrade.
- The bulletin applies only to customer-managed ADC and Gateway. Citrix says it upgrades its own cloud services and Citrix-managed Adaptive Authentication.
Don't shorten this to "SAML means vulnerable." Builds from the middle range are exposed only if they act as an IdP.
Check your configuration
Citrix says to search the appliance configuration for these entries:
- SAML SP:
add authentication samlAction - SAML IdP:
add authentication samlIdPProfile
Match what you find against your build number and the lists above. Having the string doesn't make you vulnerable on its own. Your version decides whether the SP role counts.
The fixed builds
Citrix urges affected customers to install these releases or later:
| Product | Fixed release |
|---|---|
| NetScaler ADC and Gateway | 14.1-73.46 and later |
| NetScaler ADC and Gateway | 13.1-64.29 and later 13.1 releases |
| NetScaler ADC 14.1-FIPS | 14.1-73.46 FIPS and later |
| NetScaler ADC 13.1-FIPS and 13.1-NDcPP | 13.1.37.283 and later |
Check the FIPS and NDcPP numbering carefully. Those tracks use their own build numbers and are not ordinary 13.1 builds.
One third-party write-up says the bulletin lists no workaround. The practical path is to upgrade.
Exploitation status
BleepingComputer quotes Citrix saying that, when the bulletin was published, it knew of no unmitigated exploits of this flaw. Treat that as a snapshot from 8 October, not a standing guarantee. The vendor's statement shouldn't make anyone relax.
BleepingComputer also reports that Citrix urged customers to patch two NetScaler flaws in March, days before attackers began abusing them. It says September brought updates for actively exploited NetScaler RCE zero-days, followed by an emergency fix for a denial-of-service zero-day that researchers later said could also give RCE. I haven't independently verified those earlier cases. They are BleepingComputer's account, and they show a pattern, not evidence about this CVE.
BleepingComputer also cites Shadowserver tracking over 21,000 Internet-exposed IP addresses with NetScaler fingerprints. That is nearly 20,000 ADC appliances and just over 1,500 Gateway instances. The report itself says it's unclear how many are honeypots, already patched, or configured in a vulnerable way. That figure shows how big the NetScaler footprint is. It doesn't show how many appliances are vulnerable.
What admins should do now
- Inventory every NetScaler ADC and Gateway, including Secure Private Access Hybrid back ends.
- Record each build number, including FIPS and NDcPP variants.
- Search each configuration for the two SAML strings above.
- Compare the results to the version tables to decide who is exposed.
- Schedule upgrades to the fixed builds, with the SAML-configured appliances first.
- Plan for the chance that someone gets there before you. In reporting summarised by Poppelgaard, Kevin Beaumont said compromised appliances showed a different shell on each device. Hunting for one file name or hash won't be enough. That account concerns earlier NetScaler intrusions, not confirmed attacks on this CVE.
NetScaler Console workflow
NetScaler's Console documentation describes a way to find affected instances in bulk. I couldn't retrieve that page directly, so this comes from the research notes on it:
- In NetScaler Console, open Security Advisory > CVE Detection.
- On Impacted Instances, search for
CVE-2026-107406. - Select the affected instances and choose Proceed to upgrade workflow.
- Upgrade to a release that contains the fix.
The notes say the advisory scan can take a couple of hours and that Scan-Now starts an on-demand scan. Console is a convenience for fleet management. It doesn't replace checking the target build and your SAML configuration yourself.
Bottom line
This is a critical, network-reachable memory flaw on identity-aware perimeter devices. It's patchable, and the exposure is narrower than "every NetScaler." That makes the sensible plan simple: identify the SAML-configured appliances, confirm their builds, and move them to the fixed releases before someone else does the homework for you. Citrix credits Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, for reporting the issue.
References
- Citrix warns admins to patch new NetScaler RCE flaw immediately BleepingComputer · 2026-10-09T04:27:42-04:00
- Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406 support.citrix.com
- CVE-2026-88771 through CVE-2026-88778, CVE-2026-88779 and CVE-2026-107406, what you should know and how to fix your NetScaler ADC, NetScaler Gateway - Poppelgaard.com poppelgaard.com