CVE-2026-107406
NetScaler SAML memory overflow leading to RCE or denial of service
Citrix CTX697191: memory overflow (CWE-119) in customer-managed NetScaler ADC and Gateway configured as a SAML SP or IdP, which Citrix says can lead to remote code execution or denial of service. CVSS 4.0 9.5 (Citrix), no authentication, high attack complexity. Fixed in 14.1-73.46 / 13.1-64.29 and matching FIPS/NDcPP builds. Builds that fixed CVE-2026-88779 remain affected as a SAML IdP. Not in CISA KEV. No public PoC.
- CVSS
- 9.5
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
- Class
- RCE
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Citrix
- Products
- NetScaler ADC, NetScaler Gateway
- Affected
- Customer-managed NetScaler ADC and Gateway. As SAML SP or SAML IdP: 14.1 before 14.1-73.37; 13.1 before 13.1-64.23; 14.1-FIPS before 14.1-73.37 FIPS; 13.1-FIPS/NDcPP before 13.1-37.279. As SAML IdP only: 14.1-73.37 through 14.1-73.41; 13.1-64.23 through 13.1-64.28; 14.1-73.37 FIPS through 14.1-73.41 FIPS; 13.1-FIPS/NDcPP 13.1-37.279 through 13.1-37.282. Secure Private Access hybrid deployments using these NetScaler instances are in scope. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix.
- Fixed
- 14.1-73.46 and later; 13.1-64.29 and later; 14.1-73.46 FIPS and later; 13.1-37.283 and later for 13.1-FIPS and 13.1-NDcPP.
- CWE
- CWE-119
- Published
- 8 Oct 2026
- Updated
- 9 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-107406 is a memory overflow in Citrix NetScaler ADC and NetScaler Gateway, published by Citrix in security bulletin CTX697191 on 8 October 2026. Citrix describes it as a "memory overflow vulnerability leading to Remote Code Execution or Denial of Service" and maps it to CWE-119. Citrix rates it Critical and scores it CVSS 4.0 9.5 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L. The vector means no authentication or user interaction is required, but attack complexity is high. NVD shows Citrix's score and lists the record as Received. The CVE.org record carries no CWE; the CWE comes from the bulletin.
The appliance must be configured as a SAML service provider or SAML identity provider. The required role depends on the build. On 14.1 before 14.1-73.37, 13.1 before 13.1-64.23, and the matching FIPS/NDcPP builds, either role is affected. On 14.1-73.37 through 14.1-73.41, 13.1-64.23 through 13.1-64.28, and the matching FIPS/NDcPP builds, only the SAML IdP role is affected. Citrix's checks are the samlAction (SP) and samlIdPProfile (IdP) authentication configuration entries. Fixed builds are 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1-37.283 for 13.1-FIPS and 13.1-NDcPP. Secure Private Access hybrid deployments using these NetScalers are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix. The bulletin covers supported 14.1 and 13.1 lines only and says nothing about older end-of-life branches.
The NetScaler blog says that, as of publication, Citrix is not aware of any unmitigated exploits. The CVE is not in the CISA KEV catalog. ThreatWire found no public proof-of-concept, and Beazley Security also reported none. Citrix acknowledges Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov.
This is a separate CVE and bulletin from CVE-2026-88779 (CTX697174), the exploited SAML memory overflow DoS that CISA listed in KEV on 4 October 2026. Both share CWE-119 and the SAML SP/IdP precondition. Citrix has not said whether the two are related or whether CVE-2026-107406 is an incomplete fix. Builds that fixed CVE-2026-88779 (14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282) are still affected by CVE-2026-107406 when configured as a SAML IdP.