← Back to CVE intelligence
CVE intelligence

CVE-2026-107406

Citrix NetScaler SAML memory overflow, remote code execution and denial of service

Published Oct 8, 2026Sources checked Oct 8, 2026
9.5CRITICALCVSS out of 10
What this means

Review the available evidence

CVE-2026-107406 and is rated Critical severity with a CVSS score of 9.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

Public exploit: Not collected.

What to do next

Remediation and response

  • Inventory the running build, release branch and SAML role on every ADC and Gateway node, including standby nodes and applicable Secure Private Access Hybrid instances.
  • Look for existing add authentication samlAction entries for SAML SP and add authentication samlIdPProfile entries for SAML IdP. These are configuration search patterns, not commands to run.
  • Upgrade affected deployments to the matching CTX697191 fixed build: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1.37.283 for 13.1 FIPS / NDcPP, as printed by Citrix.
  • Verify the running build, SAML sign-in and failover after the update. Preserve and investigate suspicious authentication, crash or process activity separately from patch completion.

Citrix Security Bulletins guidance

Vendor revision: Oct 8, 2026
Vendor remediation details

Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the following updated versions as soon as possible:

Vendor-listed releases

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP
CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-107406?

CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway that can allow remote code execution or interrupt service. Citrix rates it Critical, with a CVSS v4.0 score of 9.5.

Source: Citrix · Reviewed Oct 8, 2026

Affected configurations

The SAML role and running build both matter. The recent 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 builds are affected when configured as a SAML identity provider (IdP).

Older builds are affected with either a SAML service provider (SP) or IdP configuration. Citrix also lists FIPS and NDcPP editions below.

Attack requirements

Citrix's CVSS vector describes a network attack requiring no privileges or user interaction, with high attack complexity. The affected SAML configuration remains a prerequisite.

Vendor exploitation statement

At publication on October 8, Citrix said it was not aware of any unmitigated exploits of this vulnerability. This is a dated vendor statement, not evidence that an individual appliance is uncompromised.

Patch status

New fixed builds are available. The fixes previously listed for CVE-2026-88779 are within the affected IdP ranges for this separate CVE.

Check each node against CTX697191, including applicable Secure Private Access Hybrid instances. Citrix manages updates to its own cloud services.

Original NVD description

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.

NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:

* For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive

For the following versions: Applicable only when configured as a SAML SP or SAML IdP:

* NetScaler ADC and NetScaler Gateway before 14.1-73.37 * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Affected software

Products and fixed versions

Citrix guidance

Applies to Customer-managed NetScaler, including applicable Secure Private Access Hybrid instances. Configuration depends on version: the recent ranges below require SAML IdP; earlier builds require SAML SP or IdP. Fixed builds mean the listed release or a later fixed release in the same branch. Citrix prints the 13.1 FIPS / NDcPP fix as 13.1.37.283; confirm the appropriate edition in its downloads.

Product / branchAffected versionsFixed build
NetScaler ADC and Gateway14.1SAML IdP: 14.1-73.37 through 14.1-73.41 inclusive. SAML SP or IdP: before 14.1-73.37.14.1-73.46
NetScaler ADC and Gateway13.1SAML IdP: 13.1-64.23 through 13.1-64.28 inclusive. SAML SP or IdP: before 13.1-64.23.13.1-64.29
NetScaler ADC14.1 FIPSSAML IdP: 14.1-73.37 FIPS through 14.1-73.41 FIPS inclusive. SAML SP or IdP: before 14.1-73.37 FIPS.14.1-73.46 FIPS
NetScaler ADC13.1 FIPS / NDcPPCitrix groups these editions: SAML IdP on 13.1-37.279 through 13.1-37.282 inclusive; SAML SP or IdP on earlier builds. Confirm the edition against CTX697191.13.1.37.283 (vendor notation)

Use the listed fixed build or a later release in the same branch.

View Citrix advisoryReviewed Oct 8, 2026