News with an accent.

Close-up of a server cabinet with stacked equipment, small blue displays and white network cables bundled with ties.
Gabinete de servidores. Imagen de archivo.Derrick Coetzee / Wikimedia Commons (CC0) · Imagen de archivo
Privacy

Citrix fixes a critical NetScaler flaw affecting SAML setups

CVE-2026-107406 scores 9.5, and updating is the only path, because the bulletin offers no workaround and does not confirm attacks.

Citrix released patches on Oct. 8 for CVE-2026-107406, a critical memory overflow flaw in NetScaler ADC and NetScaler Gateway, according to its bulletin CTX697191. It can allow remote code execution or crash the service, and the vendor scores it 9.5 out of 10 on the CVSS v4.0 scale.

The flaw appears only if the appliance uses SAML, a single sign-on standard, either as a service provider (SP) or as an identity provider (IdP). The bulletin mentions no workaround: the path Citrix points to is updating. BleepingComputer quotes the company as saying it was not aware of any unmitigated exploits at the time of publication.

The four facts about the vulnerability:

  • CVE: CVE-2026-107406, type CWE-119.
  • Product: NetScaler ADC and Gateway with SAML SP or IdP. Hybrid Secure Private Access deployments built on NetScaler are also included.
  • Affected versions: with SAML IdP, 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28. With SAML SP or IdP, everything earlier than 14.1-73.37 and 13.1-64.23. The same applies to the FIPS and NDcPP variants.
  • Patch: yes. It is fixed in 14.1-73.46 or later and in 13.1-64.29 or later. On the FIPS builds, 14.1-FIPS 14.1-73.46 onward; on FIPS and NDcPP in the 13.1 branch, 13.1.37.283 onward.

According to the bulletin, Cloud Software Group handles updating the cloud services that Citrix manages, including Adaptive Authentication. For anyone running their own appliances, the first step is to compare their version against the list above.

A product with a track record

BleepingComputer notes that NetScaler has accumulated several exploited flaws this year, including two zero-day remote code execution bugs in September and, earlier this month, a denial-of-service flaw in the SAML module. Since November 2021, the U.S. cybersecurity agency CISA has listed 27 Citrix flaws with known exploitation, and seven were used in ransomware attacks.

NetScaler appliances usually sit at the edge of an organization's network and handle its users' remote access. Shadowserver, which tracks exposed devices, counts more than 21 000 NetScaler fingerprints visible on the internet; it is not known how many are decoys, how many have already been updated or how many have SAML enabled.

It remains to be seen whether active exploitation will emerge, which so far has not been independently confirmed, and whether Mexican organizations are affected, something no source addresses.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)