DEV Community

Anoymask
Anoymask

Posted on

Citrix NetScaler CVE-2026-107406: Pre-Authentication RCE and DoS via SAML Configuration

1. Basic Information

2. Executive Summary

A memory overflow vulnerability in NetScaler ADC and Gateway configured as a SAML IdP or SP allows unauthenticated remote attackers to trigger a denial of service (DoS) or remote code execution (RCE). Citrix urges immediate updates.

3. Attack Flow

RCE and DoS Requiring SAML Configuration

  1. An attacker sends a network request to a NetScaler instance running an affected build and configured as a SAML SP or IdP.
  2. When conditions involving high attack complexity are met, a memory overflow occurs.
  3. This may lead to a process crash resulting in a DoS, or remote code execution on the appliance.
  4. While successful RCE could theoretically lead to credential access, configuration changes, or subsequent internal network compromise, public reporting has not confirmed active exploitation.

4. Attacker Position and Execution Vector

  • An unauthenticated remote attacker with network reachability to the NetScaler SAML endpoints.

5. Impact on Users and Administrators

  • Users: May experience login failures to gateways or applications, session terminations, or service outages.
  • Administrators: May observe SAML-related requests, process crashes, core dumps, high CPU usage, or unexpected command, file, and configuration changes.

6. Conditions for Success and Failure

Conditions for Success

  • The NetScaler ADC or Gateway must run an affected build and be configured as a SAML SP or IdP.
  • The attacker must reach the service over the network and meet the conditions for high attack complexity.
  • Required SAML roles vary by build. Refer to Section 12 and CTX697191 for the specific ranges affected exclusively as an IdP.

Conditions for Failure and Mitigation

  • Update to the fixed builds designated by Citrix.
  • Restrict reachability to SAML and gateway interfaces to the minimum necessary, and disable unused SAML configurations.

7. What Happens Upon Success

  • NetScaler process crashes and remote access service denial of service (DoS).
  • Remote code execution on the appliance.
  • Potential credential theft, configuration modification, and subsequent internal network compromise originating from authentication boundary violations.

8. Observable Logs

The following items are candidates for investigation within your organization and do not represent a confirmed list of observations for this specific incident.

  • Email: No email-based initial vectors have been identified for this issue.
  • Proxy / SWG / DNS: Check for anomalous requests directed at NetScaler SAML endpoints, WAF or reverse proxy alerts, and response anomalies.
  • Endpoint / EDR: Look for NetScaler process crashes, core dumps, unexpected child processes or commands, and file or configuration modifications.
  • Identity / IdP: Review SAML assertions, IdP and SP sessions, administrator logins, unusual source locations, and credential or certificate changes.
  • SaaS / Cloud: Check advisory, configuration, and upgrade histories for NetScaler Console, Secure Private Access Hybrid, and central management platforms.
  • Network: Monitor for resets around suspected exploit requests, service disruptions, internal scans, and unusual egress traffic.

9. Determining Attack Success

Confirmed in Public Information

  • Citrix stated that it was not aware of any unmitigated exploits at the time of the bulletin's publication. This statement does not indicate reports of observed attack attempts or successful compromises.

Criteria for Internal Assessment

  • Observed Attack Attempts (Success Unconfirmed): Verify the target build and version-specific SAML configuration conditions, then correlate request contents and responses to determine if the activity constitutes an exploit attempt.
  • DoS conditions should be evaluated by linking request patterns with service stops or crashes. RCE must be determined separately through evidence such as unauthorized command or process execution, rather than relying solely on crashes.
  • Do not assume success based solely on HTTP status codes or individual alerts; correlate requests, responses, processes, authentication events, data access, and outbound traffic chronologically.

10. Investigation Playbook

  • Investigation Triggers: CVE-2026-107406 alerts, SAML endpoint anomalies, NetScaler crashes or core dumps, and Citrix advisories.
  • Initial Review: Verify the model, build, SAML SP or IdP settings, internet exposure, patch timing, and relevant requests.
  • Device and Server Forensics: Preserve crash information, core dumps, ns.log, audit logs, process lists, file integrity checks, and configuration diffs.
  • Authentication and Cloud Reviews: Check SAML sessions, administrator accounts, certificates, tokens, MFA status, and anomalous logins.
  • Post-Exploitation Tracking: Search for webshells, tunnels, credential access, internal scanning, account creation, and outbound traffic.
  • Containment: Restrict reachability to vulnerable SAML and gateway interfaces, update all instances including redundant nodes to fixed builds, and isolate systems and rotate credentials if signs of compromise are found.
  • Classification: Distinguish between attack attempts, initial execution, authentication success, data theft, and subsequent compromise; do not confirm unverified successes based on speculation alone.

11. Defense and Detection Ideas

  • Single Events: Detect SAML endpoint anomalies, memory faults, process crashes, and unexpected commands or files.
  • Chronological Correlation: Correlate anomalous requests with subsequent crashes, code execution, configuration changes, and internal access or egress traffic.
  • Threat Hunting: Search all NetScaler instances for SAML actions, IdP profiles, build versions, historical crashes, and unexpected files or processes.
  • Log Limitations: Due to TLS encryption, proprietary internal appliance processing, and high attack complexity, network logs alone are insufficient to determine exploit success.
  • Priority Mitigations: Apply fixed builds, maintain a SAML configuration inventory, restrict management plane access, preserve audit logs, and ensure redundancy.

12. Facts, Inferences, and Hypotheses

Facts

  • CVE-2026-107406 stems from improper restriction of operations within memory buffer boundaries, potentially leading to remote code execution or denial of service.
  • CVSS v4.0 score is 9.5 with the vector: AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L.
  • Exploitation requires a SAML IdP or SP configuration. Certain ranges—such as 14.1-73.37 through 73.41 and 13.1-64.23 through 64.28—are affected only when configured as a SAML IdP, while older builds are affected under either SAML SP or IdP configurations.
  • SAML SP configurations can be identified via the add authentication samlAction entry, and SAML IdP configurations via the add authentication samlIdPProfile entry.
  • Fixed builds are 14.1-73.46 for the 14.1 branch, 13.1-64.29 for the 13.1 branch, 14.1-73.46 FIPS for the 14.1-FIPS branch, and 13.1-37.283 for the 13.1-FIPS and 13.1-NDcPP branches, together with later releases in each corresponding branch.
  • Secure Private Access Hybrid utilizing NetScaler instances is also affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix and fall outside the scope of the bulletin.
  • Citrix was not aware of any unmitigated exploits at the time of the bulletin's publication.
  • Shadowserver tracks over 21,000 internet-exposed NetScaler fingerprints, though the breakdown of vulnerable configurations, unpatched states, and honeypots remains unknown.

Inferences

  • Because a SAML configuration is a prerequisite for exploitation, evaluating risk requires reviewing running configurations in addition to product version numbers.
  • Determining whether an event resulted in RCE or DoS requires correlating requests, process crashes or core dumps, unexpected commands, and configuration changes.

Hypotheses

No additional hypotheses. Unverified items are listed in Section 14.

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application medium Pre-authentication exploitation targeting network-accessible NetScaler SAML processing is expected. Active exploitation is unconfirmed.
T1499.004 Endpoint Denial of Service: Application or System Exploitation high Official impact details include DoS conditions involving process crashes.

14. Unknowns and Further Investigation

  • Specific trigger requests, affected processes, publicly available proof-of-concept (PoC) code, and evidence of active exploitation.
  • The exact count of internet-exposed instances among the over 21,000 systems that feature unpatched SAML IdP or SP configurations.
  • Persistence, credential access, and lateral movement methods that could be leveraged following successful RCE.

15. Impact on SOCs and Organizations

Because NetScaler Gateway and ADC devices sit at remote access and authentication boundaries, they represent a high priority for organizations. Establish an inventory of all instances covering not just build versions but also SAML SP and IdP configurations, and update them to fixed builds. Given past exploitation trends targeting NetScaler, organizations should also retrospectively check for pre- and post-patch crashes, core dumps, unexpected commands, webshells, and credential access activity.

16. Summary by Role

  • For SOCs: Correlate anomalous requests to SAML endpoints, process crashes, core dumps, unexpected commands, configuration modifications, and subsequent internal access.
  • For Administrators: Review SAML SP and IdP settings, and update to builds 14.1-73.46, 13.1-64.29, or corresponding FIPS and NDcPP releases and later.
  • For Users: General user action is not required. Report any gateway disruptions or unusual re-authentication prompts to administrators.

Top comments (0)