Skip to main content
CybersecurityVulnerability Management

Citrix Patches Flaw That Enables RCE in SAML Deployments

Technicians inspect equipment in a brightly-lit network operations room with rows of server racks and cables.

CVE-2026-107406 — a memory overflow scored 9.5 that can enable RCE or DoS

CVE-2026-107406 "is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The flaw carries a CVSS score of 9.5 out of 10.0, and Citrix reported that there is no evidence the issue has been exploited in the wild.

How the vulnerability is triggered: SAML IdP and SP configurations

Citrix said successful exploitation requires NetScaler instances to be configured as a SAML identity provider (IdP) or service provider (SP). Customers can check whether their instances meet that criteria by inspecting configuration entries. Citrix gave two concrete indicators to look for:

  • SAML SP: add authentication samlAction
  • SAML IdP: add authentication samlIdPProfile

The vendor also warned explicitly that "Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability," and urged customers to upgrade the affected NetScaler instances to the recommended versions to address the issue.

Affected NetScaler ADC and NetScaler Gateway releases

Citrix listed affected releases in two groupings depending on whether the appliance is configured as a SAML IdP only or as a SAML SP or IdP:

  • When configured as a SAML IdP:
    • NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
    • NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
    • NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
    • NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive
  • When configured as a SAML SP or SAML IdP:
    • NetScaler ADC and NetScaler Gateway before 14.1-73.37
    • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
    • NetScaler ADC and NetScaler Gateway before 13.1-64.23
    • NetScaler ADC 13.1-FIPS before 13.1-NDcPP 13.1-37.279

Patches and the exact releases that fix CVE-2026-107406

Citrix said the shortcoming has been addressed in the following releases and recommended customers upgrade to these versions or later:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP

Who discovered this and what other NetScaler issues matter now

Citrix credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for discovering and reporting CVE-2026-107406. The disclosure arrives against a backdrop in which Citrix previously reported that three different NetScaler ADC and NetScaler Gateway flaws — CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 — "have come under active exploitation in the wild." That contrast is sharp: for CVE-2026-107406 there is currently "no evidence that the issue has been exploited in the wild," according to Citrix.

What this means for technologists, enterprise operators, and Secure Private Access Hybrid customers

  • Technologists and security teams: Confirm whether NetScaler instances are configured as SAML IdP or SP by checking for the cited configuration entries ("add authentication samlAction" and "add authentication samlIdPProfile") and prioritize upgrades to the fixed releases Citrix lists.
  • Enterprises using Secure Private Access Hybrid and NetScaler-based remote access: Note Citrix's explicit warning that Secure Private Access Hybrid deployments using NetScaler instances are affected, and plan upgrades for the NetScaler elements of those deployments to the recommended NetScaler versions.
  • Risk managers and incident response planners: Factor this advisory into patching windows and change-control processes, balancing the high CVSS score (9.5) against Citrix's statement that there is currently no evidence of exploitation for CVE-2026-107406, while remaining attentive to the fact that other NetScaler CVEs are under active exploitation.

Citrix has published fixes and a clear checklist for identifying vulnerable SAML configurations; the immediate, concrete step the vendor recommends is to upgrade affected NetScaler instances to the specified patched releases. The disclosure also underlines that multiple NetScaler vulnerabilities exist within the same timeframe — a condition that narrows the margin for delayed patching in environments that expose SAML IdP or SP functionality.

Original advisory: https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html