Critical NetScaler RCE Vulnerability CVE-2026-107406

Critical NetScaler RCE Vulnerability CVE-2026-107406


Executive Summary

Citrix has disclosed CVE-2026-107406, a critical memory overflow vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway under specific SAML authentication configurations. The vulnerability carries a CVSS v4.0 score of 9.5 and could lead to remote code execution (RCE) or denial of service (DoS).

Citrix stated that it was not aware of any unmitigated exploitation at the time of publishing its advisory. Administrators should verify whether their appliances are affected and upgrade to the appropriate fixed builds.

What Is the Vulnerability?

CVE-2026-107406 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. Depending on the affected configuration, successful exploitation could allow an attacker to execute code remotely or disrupt appliance availability.

The issue is associated with deployments configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP). The applicable vulnerable versions depend on the software release and SAML role.

Because NetScaler appliances often provide authentication and application access for enterprise environments, a compromise could have consequences beyond the appliance itself.

Affected Products and Configurations

The vulnerability affects NetScaler ADC and NetScaler Gateway deployments that meet Citrix’s specified version and configuration conditions.

  • 14.1: Certain builds before 14.1-73.46, with specific SAML IdP conditions for builds 14.1-73.37 through 14.1-73.41.
  • 13.1: Certain builds before 13.1-64.29, with specific SAML IdP conditions for builds 13.1-64.23 through 13.1-64.28.
  • FIPS editions: Separate version ranges and fixed builds apply, including 14.1 FIPS and 13.1 FIPS/NDcPP editions.

Secure Private Access Hybrid deployments using NetScaler instances should also be reviewed.

Citrix-managed cloud services and Citrix-managed Adaptive Authentication are excluded from this advisory because Citrix manages the relevant software updates.

Consult the official bulletin for exact version-specific applicability rather than assuming every older build is affected in the same way.

How to Check Your Configuration

Citrix provides two configuration indicators that can help administrators identify whether an appliance is configured for SAML authentication.

For a SAML Service Provider:

add authentication samlAction

For a SAML Identity Provider:

add authentication samlIdPProfile

These are configuration indicators, not exploit-detection commands. Assess their presence alongside the installed build and the conditions specified in Citrix’s advisory.

Recommended Mitigation

Citrix recommends upgrading affected appliances to the appropriate fixed release.

  • NetScaler ADC and Gateway 14.1: 14.1-73.46 or later.
  • NetScaler ADC and Gateway 13.1: 13.1-64.29 or later.
  • FIPS editions: Use the corresponding fixed FIPS build specified by Citrix, including 14.1-73.46 FIPS or 13.1-37.283 FIPS, as applicable.

Before upgrading, validate the appliance edition, current build, deployment configuration, and applicable vendor instructions. Include hybrid deployments in the assessment where relevant.

Organisations should review their NetScaler inventory, prioritise externally accessible and authentication-critical appliances, and check relevant logs and monitoring data for unusual activity. Patching addresses the vulnerability, but it does not independently establish whether a system was previously compromised.

Current Exploitation Status

At the time of its advisory, Citrix reported that it was not aware of any unmitigated exploits for CVE-2026-107406.

This statement reflects the vendor’s knowledge at publication time. It is not proof that exploitation is impossible or that every deployment is safe. Security teams should continue monitoring official Citrix updates and investigate suspicious activity according to their incident response procedures.

Conclusion

CVE-2026-107406 highlights the importance of promptly reviewing security advisories for internet-facing application delivery and authentication infrastructure. Organisations running NetScaler ADC or Gateway should confirm their SAML configuration, identify affected builds, and upgrade to the appropriate fixed version.

The immediate priority is to establish exposure accurately and complete remediation before the vulnerability becomes a more significant operational or security concern.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.