Vulnerability

Critical SAML vulnerability CVE-2026-107406

On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway that use SAML authentication.

Clip path group@2x

T-Update

Information about vulnerabilities

This live blog contains information regarding a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication.

Latest blog update on 9 October
‍

Update 9 October 2026
On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication: CVE-2026-107406 (CTX697191). This vulnerability can lead to Remote Code Execution (RCE). Appliances that have already been updated for CVE-2026-88779 may also be vulnerable

Tailored cybersecurity

Background

CVE-2026-107406 is a memory overflow in NetScaler's SAML processing, with a CVSS score of 9.5. An attacker can exploit this vulnerability without authentication or user interaction, although Citrix notes that the attack complexity is high. Exploitation could lead to remote code execution or a denial-of-service.

Risk

This vulnerability can lead to Remote Code Execution (RCE). Even appliances that have already been updated for CVE-2026-88779 may still be vulnerable.

At the time of publication, Citrix stated it was “not aware of any unmitigated exploits”. This does not rule out the possibility that attempts at exploitation have occurred. A patch fixes the vulnerability but does not remove any components that an attacker may have previously installed.


‍

Advice

1. Determine whether the appliance is within scope. Check the version using 'show ns version' and the SAML configuration with:

show ns runningConfig | grep "add authentication samlAction" (SP)

show ns runningConfig | grep "add authentication samlIdPProfile" (IdP)

Check all nodes.

2. Secure evidence before updating. Capture a memory dump, core dumps from /var/core/, the log files, and a support bundle.

3. Install the patched version. Update affected appliances to 14.1-73.46, 13.1-64.29, or the specified FIPS versions. Do not forget the NetScaler instances in hybrid Secure Private Access environments.

4. Check for signs of compromise. Contact T-CERT for support.

‍

We are continuing to monitor developments and will update this advice as necessary.

Do you have questions about the potential impact on your environment, or would you like support with assessing or reconfiguring your NetScalers? Please contact T-CERT.

Ellipse 6

Sign up for T-Updates

Receive the latest news about malware or vulnerabilities in your inbox every Wednesday

More than 1,000 organizations have already joined us.

Tesorion uses your data to send the requested information. In addition, your data may be used for commercial follow-up. You can unsubscribe from this at any time via the link in the email. For more information, read our privacy policy.

Ellipse 6