If you are a NetScaler administrator, the last two weeks have felt like a treadmill: on September 27 Citrix shipped emergency fixes for two exploited zero-days (CVE-2026-88771, CVE-2026-88772), on October 3 it shipped another for a SAML zero-day (CVE-2026-88779) — and on October 8, 2026, it did it again. Bulletin CTX697191 discloses CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service on appliances configured for SAML authentication, rated CVSS 4.0 9.5 (Critical). The cruelest detail: if you patched for the October 3 zero-day and your appliance is a SAML Identity Provider, you are still vulnerable. Here is my analysis of the flaw, the version maze, and the exact builds that end the cycle.
Summary
CVE-2026-107406 is an improper restriction of operations within the bounds of a memory buffer (CWE-119) — a memory overflow — in the SAML authentication handling of NetScaler ADC and NetScaler Gateway. When the appliance is configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP), a remote attacker can trigger the overflow over the network, potentially achieving remote code execution or crashing the service. The bulletin lists no workaround.
- CVE ID: CVE-2026-107406 (Citrix security bulletin CTX697191)
- Product: Citrix NetScaler ADC and NetScaler Gateway (customer-managed appliances)
- Severity: CVSS 4.0 9.5 — Critical (scored by Citrix); NVD also lists a CVSS 3.1 score of 9.8
- Disclosed: October 8, 2026 (Citrix bulletin CTX697191); CISA revised its NetScaler alert to add this CVE on October 9, 2026
- Exploitation: Citrix states it was not aware of any unmitigated exploits at publication; not in the CISA KEV catalog as of October 9, 2026
- Workaround: None published — upgrading is the only remediation
The flaw was reported by Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with independent researcher Maxim Suhanov. Citrix-managed cloud services were updated by Citrix itself; this bulletin covers only customer-managed appliances, which you have to patch yourself.
Severity
Citrix scores this CVSS v4.0 9.5 (Critical). The published vector describes a network-reachable flaw that requires no privileges and no user interaction, but with high attack complexity — which keeps it at 9.5 rather than a perfect 10. In plain terms:
- Network attack, no credentials: the attacker talks to the appliance's SAML endpoints directly. No account on the appliance, no VPN session, nothing.
- No user interaction: nobody has to click a link or open a file. The attack is fully remote and self-contained.
- High attack complexity: exploiting a memory overflow in authentication-parsing code requires understanding the memory layout and crafting precise input — the kind of complexity that shrinks fast once researchers publish analysis. The October 3 SAML zero-day went from disclosure to "targeted attacks observed" in about 48 hours.
- Impact: RCE or DoS: Citrix says the overflow "may lead to remote code execution or denial of service." On a perimeter appliance that terminates your users' remote access sessions, either outcome is severe — code execution hands over the front door, and a crash loop locks out your remote workforce.
One honest caveat: Citrix officially characterizes only the potential for RCE, and as of October 9 there is no confirmed exploitation and no KEV listing. Do not read "not yet exploited" as "safe." The October 3 SAML zero-day went from disclosure to observed targeted attacks in about 48 hours, the precondition (SAML) is extremely common in enterprise deployments, and Shadowserver tracks more than 21,000 internet-facing NetScaler IP addresses. This is a patch-now vulnerability even without a KEV entry.
Affected Versions
Exposure depends on both the installed build and the SAML configuration. Check your SAML role in the running configuration: add authentication samlAction means SAML SP; add authentication samlIdPProfile means SAML IdP.
- NetScaler ADC and Gateway 14.1: builds 14.1-73.37 through 14.1-73.41 are affected only as a SAML IdP; builds earlier than 14.1-73.37 are affected as a SAML SP or IdP
- NetScaler ADC and Gateway 13.1: builds 13.1-64.23 through 13.1-64.28 are affected only as a SAML IdP; builds earlier than 13.1-64.23 are affected as a SAML SP or IdP
- NetScaler ADC 14.1-FIPS: matching FIPS ranges as 14.1
- NetScaler ADC 13.1-FIPS / 13.1-NDcPP: builds 13.1-37.279 through 13.1-37.282 affected as SAML IdP; earlier builds as SP or IdP
- Releases 12.1 and 13.0 are end of life and receive no fixes — if you are still on these, you are exposed with no patch coming
Fixed in: 14.1-73.46 or later, 13.1-64.29 or later, 14.1-73.46 FIPS or later, and 13.1-37.283 or later for the 13.1-FIPS/NDcPP trains. These builds also cover the earlier October bulletins, so one upgrade ends the whole cycle. Secure Private Access Hybrid deployments that use NetScaler instances are affected and need the same upgrades.
Technical Analysis
Memory overflows in authentication code are one of the oldest and most punishing vulnerability patterns in security, and the NetScaler SAML stack has now produced two of them in five days (CVE-2026-88779 on October 3, CVE-2026-107406 on October 8). That clustering is itself a finding worth dwelling on.
Think about what SAML authentication handling actually does on the appliance. When a user logs in through a federated identity provider, the NetScaler receives an XML-based SAML response — a structured, attacker-influenced blob that must be parsed, validated, and transformed into an authentication decision. Parsing attacker-controlled structured data in memory-unsafe code is precisely where buffer overflows are born: a length field trusted instead of verified, a buffer sized for the expected case but not the malicious one, a copy operation that assumes well-formed input.
Once the overflow happens, the outcome forks. At minimum, the process crashes — a denial of service against your entire remote workforce. At maximum, the attacker controls enough of the overflow to redirect execution: overwrite a return address or function pointer, point it at injected code, and the appliance guarding your front door starts running the attacker's instructions. The "high attack complexity" in the CVSS vector reflects the skill needed for that escalation — but the September NetScaler zero-days went from disclosure to webshells within days, so treat that complexity as a speed bump, not a wall.
Why the version maze matters more than the bug
Look at the affected-version table again: if you dutifully patched to 14.1-73.41 for the October 3 SAML zero-day and your appliance is a SAML Identity Provider, you are still vulnerable to this new CVE. The fixed builds for the two bulletins differ (73.41 vs 73.46), and the ranges overlap in a way that punishes anyone who patched once and stopped checking.
This is the "patch treadmill" pattern, and NetScaler has now done it three times in under two weeks. Each bulletin fixes the previous emergency's flaw while the next bulletin supersedes its build. The operational lesson is brutal but simple: for NetScaler in October 2026, the question is never "did we patch?" — it is "did we patch to the latest build, and did we re-verify after each bulletin?" Any team that treated the October 3 patch as the finish line has a vulnerable SAML IdP on their perimeter right now.
Why SAML preconditions are a configuration-inventory problem
The second structural lesson is about the precondition itself. Whether you are exposed depends not just on your build number but on whether the appliance is a SAML SP or IdP — entries buried in the running configuration (add authentication samlAction / add authentication samlIdPProfile). Most asset inventories track versions; far fewer track authentication roles per appliance. Build a query for SAML roles into your configuration management now — the next SAML bulletin will ask the same question.
Mitigation
There is no workaround in the bulletin, so this is an upgrade-or-accept-the-risk situation:
- Upgrade to the fixed builds immediately: 14.1-73.46+, 13.1-64.29+, 14.1-73.46 FIPS+, or 13.1-37.283+ (13.1-FIPS/NDcPP). One upgrade covers CVE-2026-107406 and the earlier October bulletins — do not stop at 14.1-73.41/13.1-64.28, which leaves this CVE open on SAML IdPs.
-
Audit every appliance's SAML role first. Search running configurations for
add authentication samlAction(SP) andadd authentication samlIdPProfile(IdP). Prioritize internet-facing appliances in either role; a SAML IdP on 14.1-73.37–73.41 that you already "patched" is the single most urgent box in your estate. - If you cannot patch immediately, reduce exposure. Restrict management-plane and SAML endpoint access to trusted networks where possible, and apply Citrix's Global Deny List signatures (v24 or later) as interim defense-in-depth while you schedule the upgrade.
-
Hunt for the earlier campaign while you are in there. The September/October NetScaler zero-days were actively exploited with webshells and tunneling tools; an upgrade does not remove a webshell planted before it. Check for unexpected files in LogonPoint/custom directories and review appliance logs for anomalous requests to
/saml/loginand/cgi/samlauth. - Plan the 12.1/13.0 exit. Those trains are end of life with no fixes for any of these bulletins — every month they remain on the perimeter, the exposure gap widens.
References
- AHA / Health-ISAC — Citrix Patches Critical NetScaler ADC and NetScaler Gateway Flaw (CVE-2026-107406)
- Cyber Security News — Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability
- CyberUpdates365 — Citrix NetScaler RCE CVE-2026-107406 Gets Critical Patch
- eSentire — Actively Exploited Citrix NetScaler SAML Vulnerability (CVE-2026-88779) — the October 3 predecessor bulletin
- Citrix security bulletin CTX697191 (support.citrix.com)
- NVD entry for CVE-2026-107406 (nvd.nist.gov)
Report by Faizan Akhtar — The Cyber Security Researcher
Top comments (0)