Skip to content
THREATWIRE

News

NetScaler SAML overflow CVE-2026-107406 needs new builds

Citrix CTX697191 discloses CVE-2026-107406, a critical memory overflow (CVSS 4.0 9.5) in NetScaler ADC and Gateway configured as a SAML SP or IdP that may lead to RCE or DoS. It is a new CVE, separate from the exploited CVE-2026-88779. The 88779 fix builds remain affected as a SAML IdP. Upgrade to 14.1-73.46 or 13.1-64.29. Not in KEV; Citrix is not aware of exploitation.

Critical

Published 9 Oct 2026

On this page

What happened

On 8 October 2026 Citrix published security bulletin CTX697191 for CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway. Citrix says it can lead to remote code execution or denial of service, rates it Critical, and maps it to CWE-119. Citrix scores it CVSS 4.0 9.5 with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L. No authentication is required, but attack complexity is high. NetScaler's own blog post published the same day repeats the guidance.

This is the second SAML-related NetScaler memory overflow in a week. CVE-2026-88779 (bulletin CTX697174, CVSS 4.0 8.7, denial of service) was exploited in targeted attacks and added to CISA KEV on 4 October 2026. CVE-2026-107406 is a separate CVE with its own bulletin, a higher score and a stated RCE impact.

Who is affected

Only customer-managed NetScaler ADC and Gateway configured as a SAML service provider (SP) or SAML identity provider (IdP) are affected. The required role depends on the build. Before 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, or 13.1-37.279 (13.1-FIPS/NDcPP), either SAML role is enough. From those builds through 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, or 13.1-37.282, only the SAML IdP role is affected.

The second range matters for anyone who patched last week. The builds Citrix shipped to fix CVE-2026-88779 (14.1-73.41 and 13.1-64.28 with their FIPS/NDcPP equivalents) are still affected by CVE-2026-107406 when the appliance is a SAML IdP. Secure Private Access hybrid deployments that use these NetScaler instances are in scope. Citrix upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself. The bulletin lists only the supported 14.1 and 13.1 lines and does not mention end-of-life branches.

What is confirmed

Citrix's fixed builds are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-73.46 FIPS and later, and 13.1-37.283 and later for 13.1-FIPS and 13.1-NDcPP. Citrix's way to check exposure is to look for the samlAction (SP) and samlIdPProfile (IdP) authentication entries in the appliance configuration. NetScaler Console's security advisory dashboard also lists CVE-2026-107406. Citrix acknowledges Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov.

NVD lists the CVE as Received with Citrix's 9.5 score, and the CVE.org record carries no CWE. GitHub advisory GHSA-x62m-6223-4vq2 is unreviewed. The CVE is not in the CISA KEV catalog. The NetScaler blog states that, as of publication, Citrix is not aware of any unmitigated exploits of this vulnerability. ThreatWire found no public proof-of-concept, and Beazley Security reported none at the time of writing.

What is not confirmed

There is no confirmed exploitation of CVE-2026-107406. The exploitation reports from recent weeks, including watchTowr's reproduction after honeypot activity, concern CVE-2026-88779 and the earlier CVE-2026-88771 and CVE-2026-88772, not this CVE. Citrix gives no technical detail on the overflow. It has not said whether CVE-2026-107406 is related to CVE-2026-88779, an incomplete fix for it, or a separate flaw in the same SAML code. Citrix also has not explained why the required SAML role changes at 14.1-73.37 and 13.1-64.23.

The post's summary matches the bulletin on score, preconditions, authentication, complexity and fixed builds. Some third-party summaries, including Beazley Security's executive summary, describe it as an IdP-only issue. Per Citrix, that is only true for the newer builds listed above; older builds are affected as an SP or an IdP.

What to do

Upgrade every customer-managed NetScaler ADC and Gateway configured as a SAML SP or IdP to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283 (13.1-FIPS/NDcPP) or later. This includes appliances already patched for CVE-2026-88779 that act as a SAML IdP. Citrix's bulletin offers no workaround.

Until you can upgrade, remove SAML IdP or SP configurations that are not in use and restrict access to SAML-enabled Gateway and AAA virtual servers where operationally possible. Watch for authentication service crashes or unexpected reboots. Appliances that were exposed to CVE-2026-88771, CVE-2026-88772 or CVE-2026-88779 before patching should also be assessed for compromise.

Sources: Citrix bulletin CTX697191, the NetScaler blog on CVE-2026-107406, NVD and CVE.org, GHSA-x62m-6223-4vq2, the CISA KEV catalog, and Citrix bulletin CTX697174 for CVE-2026-88779.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/netscaler-saml-overflow-cve-2026-107406-needs-new-builds

More articles