Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability
Citrix urges NetScaler ADC and Gateway customers to patch CVE-2026-107406, a critical SAML memory overflow enabling remote code execution.
Citrix bulletin CTX697191, published October 8, 2026, discloses CVE-2026-107406, a critical memory-overflow flaw (CWE-119, CVSS v4.0 9.5) in NetScaler ADC and NetScaler Gateway. Exploitation over the network requires no privileges or user interaction but has high attack complexity, and could lead to remote code execution or denial of service on appliances using certain SAML IdP or SP configurations. Citrix said it was not aware of unmitigated exploits and credited researchers from the JPMorgan Chase XOR Team and Maxim Suhanov. Customers should upgrade to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283 and later as applicable; Citrix-managed cloud services are updated by the vendor.
- CVE-2026-107406 is a CWE-119 memory overflow scored CVSS v4.0 9.5.
- Successful exploitation could allow remote code execution or denial of service.
- Exposure depends on SAML IdP or SP role and the installed build range.
- Citrix reported no known unmitigated exploits when CTX697191 was published.
- Fixed releases include 14.1-73.46, 13.1-64.29, and matching FIPS builds.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5<1%Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107406 | Memory overflow RCE/DoS in NetScaler ADC and Gateway |
Full article632 words · extracted from cybersecuritynews.com · click to collapse
Citrix has urged customers to patch a critical security flaw in NetScaler ADC and NetScaler Gateway that could allow remote code execution or cause a denial of service. Tracked as CVE-2026-107406, the memory overflow vulnerability carries a CVSS v4.0 score of 9.5 and affects appliances with specific SAML settings. The security bulletin, CTX697191, was published on October 8, 2026.
Citrix said it was not aware of any unmitigated exploits when the bulletin was published. That statement should not be read as proof that every deployment is safe. Customers still need to check both their software build and authentication settings to determine whether the flaw applies.
The bulletin classifies the issue as CWE-119, meaning software does not properly restrict operations within a memory buffer. Successful exploitation could let an attacker run code or disrupt service. Its published severity vector describes a network attack requiring no privileges or user interaction, but with high attack complexity. Citrix has not provided detailed exploit instructions in the bulletin.
Citrix credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for their work on the issue. The bulletin does not identify a specific attack campaign, victim organization, or public exploit, leaving those details outside the scope of the published advisory.
Which NetScaler Deployments Are Affected?
Exposure depends on whether NetScaler acts as a SAML identity provider, or IdP, or a service provider, or SP. These roles support single sign-on: the identity provider supplies authentication information, while the service provider uses it to grant access.
For NetScaler ADC and Gateway builds 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, the vulnerability applies only when the appliance is configured as a SAML IdP. Both ranges include their endpoints. The same condition covers NetScaler ADC 14.1-FIPS builds 14.1-73.37 through 14.1-73.41 FIPS, and 13.1-FIPS and NDcPP builds 13.1-37.279 through 13.1-37.282.

Older supported builds have broader exposure. Versions before 14.1-73.37 or 13.1-64.23 are affected when configured as either a SAML SP or SAML IdP. The corresponding thresholds are 14.1-73.37 FIPS for 14.1-FIPS appliances and 13.1-37.279 for 13.1-FIPS and NDcPP deployments.
Administrators can check their configuration for add authentication samlAction, which identifies a SAML SP configuration, or add authentication samlIdPProfile, which identifies a SAML IdP configuration. Finding either entry is not enough by itself; teams must match the setting against the applicable version range.
Fixed Versions and Patching Priorities
Citrix recommends upgrading NetScaler ADC and Gateway to 14.1-73.46 or later on the 14.1 branch, or 13.1-64.29 or later on the 13.1 branch. NetScaler ADC 14.1-FIPS customers should install 14.1-73.46 FIPS or later. For 13.1-FIPS and NDcPP, the fixed build is 13.1-37.283 or later within those branches.
Secure Private Access Hybrid deployments using affected NetScaler instances also require updates. The bulletin covers customer-managed appliances, not Citrix-managed cloud services or Citrix-managed Adaptive Authentication, which the vendor updates.
The warning follows earlier NetScaler security updates. Cyber Security News recently covered a NetScaler SAML zero-day and appliance reboots following an earlier patch. Those reports provide useful background, but their recommended builds should not replace the fixes specified for this new vulnerability.
For administrators, the key distinction is that an appliance patched for an earlier issue may still need another upgrade. Teams should use CTX697191 as the reference for this flaw, confirm the SAML role on each affected appliance, and install the matching fixed release as soon as possible.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.