Critical SAML vulnerability CVE-2026-107406
On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway that use SAML authentication.

T-Update
This live blog contains information regarding a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication.
Latest blog update on 9 October
Update 9 October 2026
On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication: CVE-2026-107406 (CTX697191). This vulnerability can lead to Remote Code Execution (RCE). Appliances that have already been updated for CVE-2026-88779 may also be vulnerable
Background
CVE-2026-107406 is a memory overflow in NetScaler's SAML processing, with a CVSS score of 9.5. An attacker can exploit this vulnerability without authentication or user interaction, although Citrix notes that the attack complexity is high. Exploitation could lead to remote code execution or a denial-of-service.
Risk
This vulnerability can lead to Remote Code Execution (RCE). Even appliances that have already been updated for CVE-2026-88779 may still be vulnerable.
At the time of publication, Citrix stated it was “not aware of any unmitigated exploits”. This does not rule out the possibility that attempts at exploitation have occurred. A patch fixes the vulnerability but does not remove any components that an attacker may have previously installed.
Advice
1. Determine whether the appliance is within scope. Check the version using 'show ns version' and the SAML configuration with:
show ns runningConfig | grep "add authentication samlAction" (SP)
show ns runningConfig | grep "add authentication samlIdPProfile" (IdP)
Check all nodes.
2. Secure evidence before updating. Capture a memory dump, core dumps from /var/core/, the log files, and a support bundle.
3. Install the patched version. Update affected appliances to 14.1-73.46, 13.1-64.29, or the specified FIPS versions. Do not forget the NetScaler instances in hybrid Secure Private Access environments.
4. Check for signs of compromise. Contact T-CERT for support.
We are continuing to monitor developments and will update this advice as necessary.
Do you have questions about the potential impact on your environment, or would you like support with assessing or reconfiguring your NetScalers? Please contact T-CERT.
Sign up for T-Updates
Receive the latest news about malware or vulnerabilities in your inbox every Wednesday
More than 1,000 organizations have already joined us.
