
Citrix fixes a critical NetScaler flaw affecting SAML setups
CVE-2026-107406 scores 9.5, and updating is the only path, because the bulletin offers no workaround and does not confirm attacks.
Citrix released patches on Oct. 8 for CVE-2026-107406, a critical memory overflow flaw in NetScaler ADC and NetScaler Gateway, according to its bulletin CTX697191. It can allow remote code execution or crash the service, and the vendor scores it 9.5 out of 10 on the CVSS v4.0 scale.
The flaw appears only if the appliance uses SAML, a single sign-on standard, either as a service provider (SP) or as an identity provider (IdP). The bulletin mentions no workaround: the path Citrix points to is updating. BleepingComputer quotes the company as saying it was not aware of any unmitigated exploits at the time of publication.
The four facts about the vulnerability:
- CVE: CVE-2026-107406, type CWE-119.
- Product: NetScaler ADC and Gateway with SAML SP or IdP. Hybrid Secure Private Access deployments built on NetScaler are also included.
- Affected versions: with SAML IdP, 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28. With SAML SP or IdP, everything earlier than 14.1-73.37 and 13.1-64.23. The same applies to the FIPS and NDcPP variants.
- Patch: yes. It is fixed in 14.1-73.46 or later and in 13.1-64.29 or later. On the FIPS builds, 14.1-FIPS 14.1-73.46 onward; on FIPS and NDcPP in the 13.1 branch, 13.1.37.283 onward.
According to the bulletin, Cloud Software Group handles updating the cloud services that Citrix manages, including Adaptive Authentication. For anyone running their own appliances, the first step is to compare their version against the list above.
A product with a track record
BleepingComputer notes that NetScaler has accumulated several exploited flaws this year, including two zero-day remote code execution bugs in September and, earlier this month, a denial-of-service flaw in the SAML module. Since November 2021, the U.S. cybersecurity agency CISA has listed 27 Citrix flaws with known exploitation, and seven were used in ransomware attacks.
NetScaler appliances usually sit at the edge of an organization's network and handle its users' remote access. Shadowserver, which tracks exposed devices, counts more than 21 000 NetScaler fingerprints visible on the internet; it is not known how many are decoys, how many have already been updated or how many have SAML enabled.
It remains to be seen whether active exploitation will emerge, which so far has not been independently confirmed, and whether Mexican organizations are affected, something no source addresses.



