CVE-2026-107406 (CVSS v4.0 9.5) is a SAML memory overflow in NetScaler ADC and Gateway. Last week's CVE-2026-88779 fix builds stay vulnerable as an IdP.
Citrix has patched CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. It scores 9.5 under CVSS v4.0 and only affects appliances configured as a SAML service provider (SP) or identity provider (IdP). The builds that fixed last week's SAML flaw, CVE-2026-88779, are still vulnerable if the appliance is a SAML IdP.
Citrix is not known to have seen exploitation, and the flaw is not on CISA's Known Exploited Vulnerabilities (KEV) catalog as of 10 October. Three earlier NetScaler flaws are on KEV, so the window to patch before that changes may be short.
What happened
Citrix published security bulletin CTX697191 on 8 October, rating the issue Critical. NVD published the CVE record on 8 October (22:17 UTC) and had not yet analysed it when we checked on 10 October; the 9.5 score is the vendor's (CNA) score. The weakness is CWE-119, improper restriction of operations within the bounds of a memory buffer. The vector is network, high attack complexity, no privileges and no user interaction (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L).
The bulletin credits Joshua Foote, Michael Tucker and Eugene Lim of the XOR Team at JPMorgan Chase. It gives no workaround; the fix is an upgrade. It also says nothing about exploitation. BleepingComputer quotes Citrix as saying that, as of publication of the bulletin, it "is not aware of any unmitigated exploits of this vulnerability." The Hacker News likewise reports no exploitation. We have not been able to read Citrix's companion blog post, which sits behind a bot check.
How it relates to the other NetScaler flaws
This is a separate CVE with its own bulletin. ThreatFrontier has covered two earlier NetScaler stories, and the three can be confused:
| CVE | Bulletin | Impact | On KEV | Our coverage |
|---|---|---|---|---|
| CVE-2026-88771, CVE-2026-88772 | CTX697096 (27 Sep) | Zero-days | Yes, 27 Sep | Citrix NetScaler zero-days |
| CVE-2026-88779 | CTX697174 (3 Oct) | SAML memory overflow, denial of service | Yes, 4 Oct | CVE-2026-88779 on KEV |
| CVE-2026-107406 | CTX697191 (8 Oct) | SAML memory overflow, RCE or DoS | No | this article |
Citrix's bulletin for CVE-2026-107406 does not say it is related to CVE-2026-88779, and a separate bulletin means a separate fix. Both are SAML memory overflows with the same SP/IdP precondition, so one check covers both exposures, but patching one does not patch the other. SAML bugs are not unique to NetScaler; we covered a SAML signature wrapping flaw in GitHub Enterprise Server.
Who is exposed
An appliance is in scope only if it is a SAML SP or IdP and runs an affected build. Which builds depend on the role:
| Product line | SAML IdP only affected | SP or IdP affected | Fixed in |
|---|---|---|---|
| ADC and Gateway 14.1 | 14.1-73.37 to 14.1-73.41 | before 14.1-73.37 | 14.1-73.46 and later |
| ADC and Gateway 13.1 | 13.1-64.23 to 13.1-64.28 | before 13.1-64.23 | 13.1-64.29 and later of 13.1 |
| ADC 14.1-FIPS | 14.1-73.37 FIPS to 14.1-73.41 FIPS | before 14.1-73.37 FIPS | 14.1-73.46 FIPS and later |
| ADC 13.1-FIPS and 13.1-NDcPP | 13.1-NDcPP 13.1-37.279 to 13.1-37.282 | before 13.1-NDcPP 13.1-37.279 | 13.1.37.283 and later |
Which NetScaler builds are exposed, by SAML role (Citrix CTX697191).
All ranges are inclusive and come from CTX697191. Secure Private Access Hybrid deployments that use NetScaler instances are also affected. The bulletin covers customer-managed appliances only; Cloud Software Group upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself.
Last week's fix is not this week's fix
The "IdP only" band is the part most likely to catch administrators out. Our earlier report, citing bulletin CTX697174, gave the CVE-2026-88779 fixed builds as 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282. Every one of them sits inside the IdP-only band above, because the band ends at exactly those builds.
So, from the two bulletins:
- An appliance acting as a SAML IdP that upgraded to the CVE-2026-88779 fix is still affected by CVE-2026-107406.
- An appliance acting only as a SAML SP on 14.1-73.37 or later, or 13.1-64.23 or later, is not affected by this CVE according to the bulletin. That includes the September builds.
- Appliances on anything older than the September builds are affected in either role.
The bulletin text does not list 14.1 builds between 73.42 and 73.45, but Citrix's CVE record marks every build below 14.1-73.46 as affected, and it does not say for which SAML role. Treat those builds as vulnerable and target 14.1-73.46 or later.
Technical details
Citrix's description is short: "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service". The bulletin does not say which request or which SAML message triggers the overflow, how reliable code execution is, or which process crashes. No proof of concept or technical write-up from the finders had surfaced in the sources we checked.
What the vector tells us: the network vector, no privileges and no user interaction mean the attacker needs no account on the appliance. The high attack complexity means the attacker has to meet some condition beyond reaching the SAML endpoint; Citrix does not say what. The CNA scores confidentiality, integrity and availability impact on the vulnerable system as high, consistent with code execution rather than only a crash.
Citrix gives two configuration lines to find out whether an appliance meets the SAML precondition. Run a search of the saved configuration (ns.conf) for either:
add authentication samlAction (appliance is a SAML SP)
add authentication samlIdPProfile (appliance is a SAML IdP)
Why it matters
NetScaler ADC and Gateway sit on the network edge and terminate remote access and single sign-on. A memory flaw reachable without credentials on such a device is a high-value target (compare the exploited Ivanti Connect Secure overflow): CVE-2026-88771 and CVE-2026-88772 were added to KEV on 27 September and CVE-2026-88779 on 4 October. CISA's SSVC entry in the NVD record (9 October) lists exploitation as none. Nothing in our sources links this CVE to those attacks, and we are not saying it is exploited.
On scale, BleepingComputer cites Shadowserver tracking over 21,000 IP addresses with NetScaler fingerprints, just over 1,500 Gateway and nearly 20,000 ADC. That count is not limited to SAML-configured appliances, so it overstates the exposed population for this flaw; it shows the size of the NetScaler footprint. BleepingComputer says it has no information on how many are honeypots, already patched or vulnerably configured.
What defenders should do
- Find SAML appliances. Search
ns.confforadd authentication samlActionandadd authentication samlIdPProfileon every ADC, Gateway and SPA Hybrid NetScaler instance. Note which role each plays. - Upgrade to the fixed build for your line: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1.37.283 for 13.1-FIPS and 13.1-NDcPP, or any later release of the same line. Prioritise IdP appliances and internet-facing ones.
- Do not treat the CVE-2026-88779 upgrade as done. If an IdP was moved to 14.1-73.41 or 13.1-64.28 last week, it needs another upgrade. For SP-only appliances already on September's builds or later, the bulletin lists no exposure to this CVE.
- Do not wait for a workaround. The bulletin states none, and its metadata marks the article as having no workaround solution. Disabling SAML would remove the precondition in principle, but Citrix does not offer that as guidance and it would break SSO, so treat the upgrade as the fix.
- Keep watching KEV. If CISA adds the CVE, federal deadlines follow, and the exploitation picture changes. For the earlier SAML flaw, signs of attack in the logs and appliance reboots were reported; the earlier article lists the log patterns researchers used. They have not been tied to this CVE.
What is still unclear
- Exploitation. Citrix says it knows of no unmitigated exploits, KEV did not list the CVE when we checked, and CISA's SSVC assessment in the NVD record (9 October) rates exploitation "none", automatable "no" and technical impact "total". Both statements are dated and can change.
- Mechanism and difficulty. The bulletin does not describe the trigger or what makes the attack complex.
- Builds 14.1-73.42 to 14.1-73.45. The bulletin text omits them, but Citrix's CVE record marks them affected without naming the SAML role.
- NVD analysis. NVD's own assessment was pending, and the CVE record's affected-version data writes the FIPS fix as "13.1.37.283 FIPS" while the bulletin says "13.1.37.283" for both 13.1-FIPS and 13.1-NDcPP. We follow the bulletin.
- Companion blog. Citrix's related blog post was not readable to us, so any extra guidance there is not reflected here.
Sources
- Citrix security bulletin CTX697191
- NVD record for CVE-2026-107406 (API)
- CISA Known Exploited Vulnerabilities feed (checked 10 October; feed dated 8 October)
- Citrix blog on CVE-2026-107406 (linked from the bulletin; not readable to us)
- BleepingComputer coverage (secondary; Citrix quote and Shadowserver figure)
- The Hacker News coverage (secondary)