Vulnerability

Critical SAML vulnerability CVE-2026-107406

On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway that use SAML authentication.

Clip path group@2x

T-Update

Information about vulnerabilities

This live blog contains information regarding a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication.

Latest blog update on 9 October
‍

Update 9 October 2026
On 8 October 2026, Citrix published a new critical vulnerability in NetScaler ADC and NetScaler Gateway using SAML authentication: CVE-2026-107406 (CTX697191). This vulnerability can lead to Remote Code Execution (RCE). Appliances that have already been updated for CVE-2026-88779 may also be vulnerable

‍

Customized cyber security

Background

CVE-2026-107406 is a memory overflow in NetScaler's SAML processing, with a CVSS score of 9.5. An attacker can exploit this vulnerability without authentication or user interaction, although Citrix notes that the attack complexity is high. Exploitation could lead to remote code execution or a denial-of-service.

Risk

This vulnerability can lead to Remote Code Execution (RCE). Even appliances that have already been updated for CVE-2026-88779 may still be vulnerable.

At the time of publication, Citrix stated it was “not aware of any unmitigated exploits”. This does not rule out the possibility that attempts at exploitation have occurred. A patch fixes the vulnerability but does not remove any components that an attacker may have previously installed.


‍

‍

Advice

1. Determine whether the appliance is within scope. Check the version using 'show ns version' and the SAML configuration with:

show ns runningConfig | grep "add authentication samlAction" (SP)

show ns runningConfig | grep "add authentication samlIdPProfile" (IdP)

Check all nodes.

2. Secure evidence before updating. Capture a memory dump, core dumps from /var/core/, the log files, and a support bundle.

3. Install the patched version. Update affected appliances to 14.1-73.46, 13.1-64.29, or the specified FIPS versions. Do not forget the NetScaler instances in hybrid Secure Private Access environments.

4. Check for signs of compromise. Contact T-CERT for support.

‍

We are continuing to monitor developments and will update this advice as necessary.

Do you have questions about the potential impact on your environment, or would you like support with assessing or reconfiguring your NetScalers? Please contact T-CERT.

‍

Ellipse 6

Sign up to receive T-Updates

Receive the latest vulnerabilities in your email every Wednesday

More than 1,000 organisations have already joined us.

Tesorion gebruikt jouw gegevens voor het versturen van de gevraagde informatie. Daarnaast worden je gegevens mogelijk gebruikt voor commerciële opvolging. Je kunt je op elk gewenst moment hiervoor afmelden via de link in de e-mail. Lees voor meer informatie ons privacybeleid.

Ellipse 6