Citrix patches critical NetScaler SAML flaw that can lead to code execution
CVE-2026-107406, rated 9.5 under CVSS v4.0, affects NetScaler ADC and NetScaler Gateway appliances set up for SAML. Citrix says it knows of no unmitigated exploits so far and asks customers to update quickly.

Key points
- 1CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service; Citrix rates it 9.5 (CVSS v4.0).
- 2Only appliances configured as a SAML service provider or identity provider are affected; on recent builds only the identity provider role is vulnerable.
- 3Fixed releases include 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1.37.283 for 13.1-FIPS and 13.1-NDcPP, or later.
- 4Citrix says it is not aware of unmitigated exploits so far; The Register notes Citrix did not say whether it was used as a zero-day before disclosure.
- 5Citrix updates its own managed cloud services and Adaptive Authentication; customer-run appliances, including Secure Private Access Hybrid instances, must be upgraded by their owners.
Full story
Citrix has published a security bulletin for CVE-2026-107406, a vulnerability in NetScaler ADC and NetScaler Gateway. The bulletin describes it as a memory overflow that can lead to remote code execution or denial of service, files it under CWE-119, a class of memory buffer weaknesses, and gives it a CVSS v4.0 base score of 9.5. The bulletin covers only appliances that customers run themselves; Cloud Software Group, the company behind Citrix, says it applies the updates to the cloud services and Adaptive Authentication that Citrix manages on its own.
An appliance is only exposed when it acts as a SAML service provider (SP) or SAML identity provider (IdP), and which role matters depends on the build. On builds older than 14.1-73.37 and 13.1-64.23, and on FIPS builds older than 14.1-73.37 FIPS and 13.1-37.279, both roles are affected. On the newer builds 14.1-73.37 to 14.1-73.41 (including the 14.1-FIPS equivalents), 13.1-64.23 to 13.1-64.28 and the 13.1-FIPS/NDcPP builds 13.1-37.279 to 13.1-37.282, only the identity provider role is vulnerable, according to Citrix.
Citrix lists these fixed releases: 14.1-73.46 or later for the 14.1 branch, 13.1-64.29 or later within 13.1, 14.1-73.46 FIPS or later for 14.1-FIPS, and 13.1.37.283 or later for the 13.1-FIPS and 13.1-NDcPP editions. NetScaler instances that are part of Secure Private Access Hybrid deployments are affected as well and need the same upgrade. To find out whether a device uses either SAML role, Citrix says administrators can look in its configuration for entries matching add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider).
On exploitation, Citrix said in a statement quoted by BleepingComputer: “As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability”. The Register notes that Citrix did not say whether the flaw had been used as a zero-day before it was disclosed. The bulletin credits researchers from the XOR Team at JPMorgan Chase. BleepingComputer reports that Shadowserver tracks more than 21,000 IP addresses with NetScaler fingerprints on the internet, nearly 20,000 of them ADC appliances and just over 1,500 Gateway instances, but it is not known how many are honeypots, already patched or set up in a vulnerable way.
The fix follows several NetScaler flaws that attackers have used this year. Earlier this month Citrix shipped emergency updates for CVE-2026-88779, a denial-of-service zero-day that The Register says carries a score of 8.7 and that researchers and administrators later said also allowed code execution, according to BleepingComputer. Per The Register, that flaw and the new one both involve memory overflows in SAML configurations. In September Citrix fixed two exploited zero-days, CVE-2026-88771 and CVE-2026-88772; Google researchers said a campaign abusing CVE-2026-88772 had been running since at least early September. BleepingComputer adds that since November 2021 CISA has listed 27 Citrix vulnerabilities as actively exploited, seven of them in ransomware attacks.
Why it matters
NetScaler ADC and Gateway sit at the network edge, and attackers exploited several NetScaler flaws in recent weeks, some before patches existed. Citrix reports no exploitation of this flaw so far, but it scores higher than CVE-2026-88779, which was exploited. Shadowserver sees more than 21,000 NetScaler systems online, though it is unclear how many run a vulnerable SAML setup. Organisations that run their own appliances need to check their build and SAML role and update.
Timeline
· Published
Topics#Citrix#NetScaler#CVE-2026-107406#Vulnerabilities#SAML
Sources
This story draws on the following sources. Read them for full context.
- 1Citrix (Cloud Software Group) · Primary sourceCitrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406support.citrix.com
- 2The Register · News reportCitrix gives NetScaler admins another critical reason to patchwww.theregister.com
- 3BleepingComputer · News reportCitrix warns admins to patch new NetScaler RCE flaw immediatelywww.bleepingcomputer.com



