Back to Articles
critical CVE-2026-107406

CRITICAL: Citrix NetScaler SAML Flaw CVE-2026-107406 Enables RCE

Citrix patched CVE-2026-107406, a CVSS 9.5 memory overflow in NetScaler ADC and Gateway that can lead to remote code execution on appliances configured as a SAML identity provider or service provider. It lands days after the exploited CVE-2026-88779 in the same SAML code, so upgrade to 14.1-73.46 or 13.1-64.29 now.

By Danny Mercer, CISSP — Lead Security Analyst • Oct 9, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

If you manage a NetScaler fleet, you may want to sit down for this one. Less than a week after Citrix confirmed that attackers were already hammering SAML-enabled appliances through CVE-2026-88779, the company is back with another bulletin for the exact same corner of the product. This time the bug is rated more severely, the impact language includes the words "remote code execution," and the affected configuration is one that a very large number of enterprises run on purpose because it is how they hook their remote access into single sign-on.

The new flaw is tracked as CVE-2026-107406 and carries a CVSS v4.0 score of 9.5. Citrix describes it plainly: "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions." Those specific conditions are SAML, and if your NetScaler ADC or NetScaler Gateway is acting as a SAML identity provider or a SAML service provider, you are in scope. Appliances with no SAML configuration at all are not affected, which is the only genuinely good news in the advisory.

What Citrix Fixed and Who Is Exposed

The version picture is a little more nuanced than usual, so it is worth reading slowly. On the 14.1 branch, every NetScaler ADC and Gateway build before 14.1-73.37 is vulnerable whether the appliance is configured as a SAML service provider or as a SAML identity provider. Builds 14.1-73.37 through 14.1-73.41 are still vulnerable, but only when the box is acting as a SAML identity provider. The same split applies on the 13.1 branch, where anything before 13.1-64.23 is exposed in either SAML role and builds 13.1-64.23 through 13.1-64.28 remain exposed in the identity provider role. The FIPS and NDcPP builds follow the same pattern, with 14.1-FIPS builds before 14.1-73.46 FIPS affected and 13.1-FIPS and 13.1-NDcPP builds before 13.1-37.283 affected.

That split matters because a lot of teams patched aggressively over the past couple of weeks and may be feeling pretty good about themselves right now. If you jumped to 14.1-73.37 or 13.1-64.23 and your appliance is only a SAML service provider, you closed the door on this particular bug. If your NetScaler is the identity provider, handing out assertions to downstream applications, you are still holding an open ticket. Citrix also notes that Secure Private Access hybrid deployments built on affected NetScaler instances are in scope, so do not assume the cloud side of a hybrid setup shields the on-premises appliance.

The fixed builds are NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, 13.1-64.29 and later, NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.283 and later. If you are still running anything on the 12.1 or 13.0 trains, those reached end of life a long time ago, and the honest answer is that you need to be on a supported branch before patching even becomes a conversation.

Credit for the discovery goes to Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR team, along with independent researcher Maxim Suhanov. It is always encouraging to see a large bank's offensive team pointing its talent at the gear that the rest of the industry depends on, and reporting what it finds instead of quietly mitigating and moving on.

Why This One Deserves Your Weekend

As of publication, Citrix says it is not aware of exploitation of CVE-2026-107406 in the wild. That sentence should comfort you for about as long as it takes to remember the context. In the last few weeks Citrix has had to patch CVE-2026-88771 and CVE-2026-88772, both exploited, and then CVE-2026-88779, a memory overflow in the same SAML handling that was being used against customer-managed appliances before a fix existed. CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog on October 5 and gave federal agencies just two days to remediate, which tells you how seriously the government read the situation.

Attackers are clearly already fuzzing, diffing, and probing the NetScaler SAML parser. When a vendor ships a second memory corruption fix in the same component days after the first, the people who reverse engineered the first patch are going to diff the second one almost immediately. The window between "no known exploitation" and "proof of concept on GitHub" for NetScaler bugs has historically been measured in days, and anyone who lived through Citrix Bleed in 2023 remembers how fast that went from advisory to mass session hijacking. A bug that can reach remote code execution on an internet facing authentication gateway is about the most valuable thing an initial access broker can hold.

It is also worth being clear eyed about what a successful exploit means. NetScaler Gateway sits at the edge, terminates TLS, brokers authentication, and in many environments holds the keys to Citrix Virtual Apps, internal web applications, and VPN access all at once. Code execution on that box is not a foothold on a random server. It is a seat at the front door with the ability to watch credentials and session tokens walk past. The CVE-2026-88779 campaign was officially characterized as denial of service, but researchers reported attack traffic carrying web shell deployment scripts and appliance data collection commands. Whether those payloads worked through that bug or not, the intent of the people knocking was obvious.

What to Do Right Now

Start by figuring out which of your appliances actually use SAML. Citrix gives you a simple test. Search the running configuration for the string "add authentication samlAction," which indicates the appliance is a SAML service provider, and for "add authentication samlIdPProfile," which indicates it is acting as a SAML identity provider. Any hit means the appliance needs to move to a fixed build. If you manage a lot of tenants, script that check through your RMM or NetScaler Console and get a real inventory instead of relying on whatever the documentation from the original deployment says.

Then patch, and prioritize the identity provider appliances first because they are vulnerable across a wider range of builds, including ones that many teams just upgraded to. Upgrade to 14.1-73.46 or 13.1-64.29 at a minimum, or the matching FIPS and NDcPP builds where compliance requires them. Citrix has not published a configuration workaround that preserves SAML functionality, so if a maintenance window is truly impossible in the next day or two, the only real interim option is to restrict who can reach the authentication virtual servers at the network level and accept the business impact.

Because there is an actively exploited sibling bug in the same code path, treat any SAML-enabled appliance that sat unpatched over the last two weeks as a candidate for compromise review rather than simply patching and walking away. Look for unexpected files under the web directories such as /var/netscaler/logon and /var/vpn, unfamiliar PHP or shell scripts, new cron entries, and unexplained crashes or restarts of the nsppe packet engine processes, which can show up as core dumps under /var/core. Review authentication logs for unusual SAML assertion sizes or malformed requests, and check for administrative logins or configuration changes you cannot account for. If you find anything suspicious, take a forensic image before you rebuild, and rotate any credentials and session secrets that the appliance could have seen, including the SAML signing certificates.

After patching, kill active sessions. That lesson was learned the hard way with Citrix Bleed, where organizations patched but left stolen session tokens valid for days. Clearing sessions with the "kill aaa session -all" and "kill icaconnection -all" commands, along with the equivalent for any RDP or PCoIP proxy sessions, costs your users one reauthentication and removes a whole category of follow-on risk.

Finally, put detection on the edge where it belongs. Forward NetScaler syslog to your SIEM if it is not already there, alert on packet engine crashes, and watch for outbound connections from the appliance to destinations it has no business talking to. A NetScaler should be pretty boring on the network. When it starts behaving interestingly, somebody needs to get paged.

The Bigger Picture

Edge devices continue to be the soft underbelly of the enterprise. Citrix, Ivanti, Fortinet, Palo Alto, and Cisco have all spent the past three years shipping emergency fixes for the very appliances that are supposed to keep attackers out, and the pattern is not slowing down. NetScaler's SAML implementation has now produced multiple memory corruption bugs in a matter of weeks, which strongly suggests that researchers on both sides of the line have found a productive vein and are going to keep mining it. Expect more advisories, and build your patch cadence for edge appliances around days, not the monthly window you use for workstations.

Drop everything and patch this now, and then go check whether anybody beat you to the box.

MSP Angle

A second critical NetScaler SAML bug in one week is a natural opening for an edge device inventory and emergency patching engagement with clients who host their own Citrix infrastructure, along with a paid compromise assessment for any appliance that sat exposed. It is also a strong argument for selling continuous external attack surface monitoring, since most clients cannot tell you offhand which of their appliances run SAML or which build they are on.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →