Vulnerability
Published 2026-10-08
Verified 2026-10-09

Citrix NetScaler CVE-2026-107406 (CVSS 9.5): SAML SP/IdP memory overflow can lead to remote code execution or DoS — CTX697191; patch to 14.1-73.46 / 13.1-64.29 (and FIPS peers); no known exploitation at publication

Citrix Security Bulletin CTX697191 (published 8 October 2026) assigns CVE-2026-107406 to a memory-overflow flaw (CWE-119) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a SAML service provider or identity provider. CVSS v4.0 base 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L). Successful abuse can lead to remote code execution or denial of service. Exposure is version-specific: builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 (and matching FIPS/NDcPP ranges) are affected only as SAML IdP; older supported builds before those floors are affected as either SAML SP or IdP. Citrix urges upgrades to 14.1-73.46 or later, 13.1-64.29 or later, 14.1-73.46 FIPS or later, and 13.1-37.283 or later for 13.1-FIPS/NDcPP. Secure Private Access Hybrid deployments that use affected NetScaler instances also need the upgrade. Customer-managed appliances only; Citrix-managed cloud and Adaptive Authentication are updated by Citrix. Check config for add authentication samlAction (SP) or add authentication samlIdPProfile (IdP). Citrix said it was not aware of unmitigated exploits at publication. Distinct from earlier SAML DoS CVE-2026-88779 (desk card citrix-netscaler-saml-acsc-20261003). Primary: Citrix CTX697191; wire: Cyber Security News.

Product
Citrix NetScaler ADC and NetScaler Gateway (SAML SP/IdP configurations)
Versions
Patch to 14.1-73.46+, 13.1-64.29+, 14.1-73.46 FIPS+, 13.1-37.283+ (FIPS/NDcPP); see CTX697191 for which SAML roles apply by build
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade customer-managed NetScaler ADC/Gateway to the fixed builds in CTX697191. Confirm whether the appliance is a SAML SP or IdP (samlAction / samlIdPProfile), prioritise internet-facing Gateway/AAA, and treat this as separate from the earlier CVE-2026-88779 SAML crash patches.

Primary: Citrix Security Bulletin CTX697191 — CVE-2026-107406 NetScaler ADC/Gateway (8 Oct 2026) · Vendor: Citrix Community — Immediate guidance for CVE-2026-107406 (linked from bulletin) · CVE: CVE-2026-107406, CVE-2026-88779 · Cyber Security News — Citrix urges NetScaler ADC and Gateway customers to patch critical RCE (9 Oct 2026)

vulnerabilities network identity cloud