TL;DR
Citrix has published a critical bulletin for CVE-2026-107406, a memory overflow flaw in NetScaler ADC and NetScaler Gateway rated 9.5 on CVSS v4.0. This Citrix NetScaler vulnerability “may lead to remote code execution or denial of service” on appliances set up for SAML. Citrix urges customers to upgrade as soon as possible.
- CVE: CVE-2026-107406
- CVSS: 9.5 (Critical Β· CVSSv4)
- Product: NetScaler ADC
- Affected: < 14.1-73.46, < 13.1-64.29, < 14.1-73.46 FIPS, < 13.1.37.283 FIPS
- Impact: Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- Status: No confirmed exploitation yet
- Patched in: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, 13.1.37.283 FIPS
- Action: Update to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, 13.1.37.283 FIPS now
Track every Citrix CVE the moment it's exploited.
Get free email alertsWhy It Matters
NetScaler appliances sit at the network edge and handle remote access for many organizations. They have also been frequent targets in past attack campaigns. According to the Citrix customer guidance, Citrix “is not aware of any unmitigated exploits of this vulnerability” so far.
How the Attack Works
Citrix describes the bug as a memory overflow. It only applies under “specific configuration conditions,” namely when the appliance acts as a SAML service provider (SP) or SAML identity provider (IdP). Citrix has not shared further technical details. However, the version list shows a split. On the newest affected builds, only the IdP role is exposed. Older builds are at risk in either role. Appliances with no SAML setup are not affected at all.
Affected Versions
Exposure depends on both version and SAML role:
- SAML IdP only: 14.1-73.37 to 14.1-73.41, and 13.1-64.23 to 13.1-64.28, plus matching FIPS and NDcPP builds
- SAML SP or IdP: builds before 14.1-73.37 and before 13.1-64.23, plus matching FIPS and NDcPP builds
Secure Private Access hybrid deployments that use NetScaler are also affected. Citrix-managed cloud services and Adaptive Authentication are not, since Citrix updates them itself.
Patch and Mitigation Steps
First, check whether the Citrix NetScaler vulnerability applies. Look for “add authentication samlAction” (SP) or “add authentication samlIdPProfile” (IdP) in the configuration. If either appears on an affected build, upgrade to the fixed releases listed in Citrix’s security bulletin. Given NetScaler’s history, treat this Citrix NetScaler vulnerability as urgent.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!