Citrix published a bulletin on October 8 for CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. The bulletin rates it Critical at CVSS v4.0 9.5.
What happened
According to Citrix’s security bulletin CTX697191, the flaw only affects appliances configured as a SAML service provider or a SAML identity provider, with different version ranges for each role. Appliances running builds before 14.1-73.37 or 13.1-64.23 are affected in either role. For the identity provider role only, builds from 14.1-73.37 through 14.1-73.41 and from 13.1-64.23 through 13.1-64.28 are also affected, along with the matching FIPS and NDcPP builds. Secure Private Access Hybrid deployments that use NetScaler instances are affected too.
The fixed releases are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later. Citrix-managed cloud services are upgraded by Cloud Software Group, which owns Citrix.
Why it matters
NetScaler has been in the news for weeks. The UK’s NCSC urged organizations on September 28 to mitigate eight other NetScaler vulnerabilities, two of them confirmed as exploited. We covered CISA’s listing of the SAML-related flaw CVE-2026-88779 and the reports tracing NetScaler attack activity to August 21. The Citrix bulletin we reviewed does not say whether CVE-2026-107406 is being exploited.
One original point
The 14.1-73.41 and 13.1-64.28 builds were the cutoff for the earlier SAML flaw, so a team that patched to them last week can reasonably believe it is current. Under this bulletin those same builds remain affected if the appliance acts as a SAML identity provider. The version number alone does not settle it; the role does.
What to do
Citrix tells customers to search the appliance configuration for an entry beginning add authentication samlAction for the service provider role, or add authentication samlIdPProfile for the identity provider role, and to install a fixed build as soon as possible. Check both roles on every appliance.