Back to vendor advisories
Citrix Security BulletinsCTX697191

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406

CriticalVendor CVSS 9.5 / 10 1 CVE Published Oct 8, 2026 at 3:03 PM UTC

Summary

Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability identified below

Products covered

  • Citrix NetScaler ADC and Citrix NetScaler Gateway

  • The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability if they meet the following conditions: NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: For the following versions: Applicable only when configured as a SAML IdP: NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: NetScaler ADC and NetScaler Gateway before 14.1-73.37 NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS NetScaler ADC and NetScaler Gateway before 13.1-64.23 NetScaler ADC 13.1-FIPS before 13.1-NDcPP 13.1-37.279

Remediation

Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the following updated versions as soon as possible:

Vendor-listed fixes

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1

  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS

  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP

CVEs in this advisory 1

Update history

What changed in later vendor updates

SecurityAlert records field-level changes from the point we begin following a bulletin. Earlier vendor changes may not have a field-by-field record.

    • Added affected products: The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability if they meet the following conditions: NetScaler ADC or NetScaler Gateway must be configured as a....
    • Removed affected products: The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerability if they meet the following conditions: NetScaler ADC or NetScaler Gateway must be configured as a....

Updates

  1. Published by Citrix

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.

  3. Confirmed at the source

    Our collector saw this advisory during a later source check.