Citrix has issued fixes for CVE-2026-107406, a critical memory overflow in NetScaler ADC and NetScaler Gateway that can give an unauthenticated attacker remote code execution on appliances using SAML. It is the fourth serious NetScaler issue in a matter of weeks, and some organisations that patched in September are still exposed.
What happened
On 8 October 2026, Cloud Software Group published security bulletin CTX697191 covering CVE-2026-107406, a flaw in customer-managed NetScaler ADC and NetScaler Gateway. The company rates it critical, with a CVSS v4.0 base score of 9.5, and describes it as a memory overflow that can lead either to remote code execution or to a denial of service. Citrix published an accompanying blog the same day urging customers to upgrade without delay, and both BleepingComputer and SecurityWeek reported the bulletin on 9 October.
Citrix says that, at the time of publication, it was not aware of any unmitigated exploits, and BleepingComputer reports the vendor had found no evidence of exploitation in the wild. That is the good news. The less comforting context is the recent record: NetScaler customers have already dealt with two exploited zero-days (CVE-2026-88771 and CVE-2026-88772) in late September and a further denial-of-service zero-day, CVE-2026-88779, earlier this month. Back in March, CVE-2026-3055 and CVE-2026-4368 were patched and then abused within days.
The bug was reported to Citrix by Joshua Foote, Michael Tucker and Eugene Lim of the XOR Team at JPMorgan Chase, according to the advisory’s acknowledgements.
The technical picture
Citrix maps the vulnerability to CWE-119, the weakness class for memory buffer bounds errors. The CVSS vector indicates network access with no privileges and no user interaction required, but with high attack complexity, and with high impact on confidentiality, integrity and availability, with knock-on effects for connected systems. In plain terms: an attacker who can reach the right listener does not need credentials, but conditions have to line up for reliable exploitation.
Exposure depends on how the appliance is used for SAML single sign-on. Citrix splits affected builds into two groups:
- Older builds (14.1 before 14.1-73.37, 13.1 before 13.1-64.23, and the equivalent FIPS and NDcPP releases) are vulnerable when configured as either a SAML Service Provider or a SAML Identity Provider.
- Recent builds from 14.1-73.37 to 14.1-73.41 inclusive, and from 13.1-64.23 to 13.1-64.28 inclusive (plus matching FIPS builds), are vulnerable only when acting as a SAML Identity Provider.
That second group matters. Builds 14.1-73.37 and 13.1-64.23 are the first releases fixing the exploited September zero-days that the NCSC warned UK organisations about on 28 September. Anyone who patched promptly then, and who runs their NetScaler as a SAML IdP, is still in scope for this new flaw.
Fixed releases are 14.1-73.46 and later, 13.1-64.29 and later, 14.1-73.46 FIPS, and 13.1.37.283 for 13.1-FIPS and 13.1-NDcPP. Citrix also flags Secure Private Access Hybrid as affected wherever it relies on NetScaler, so those instances need upgrading too. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are being updated by the vendor.
The bulletin explains how to confirm the precondition: administrators can search the running configuration for SAML action entries (indicating a Service Provider role) or SAML IdP profile entries (indicating an Identity Provider role).

Why it matters for UK organisations
NetScaler Gateway is one of the most common front doors for remote access in the UK, sitting in front of virtual desktops, intranets and line-of-business applications across local government, the NHS, universities, law firms and financial services. Using it as a SAML IdP or SP is a routine way to bolt it into Entra ID or another identity platform, so the vulnerable configuration is hardly exotic.
Shadowserver currently tracks more than 21,000 internet-exposed IP addresses with NetScaler fingerprints, roughly 1,500 of them Gateway instances and nearly 20,000 ADC appliances, according to BleepingComputer. That figure is global and does not tell us how many are patched, honeypots or configured for SAML, but it gives a sense of scale.
The NCSC has repeatedly flagged NetScaler issues this year, publishing alerts in March and again on 28 September, when it said it was working to understand the impact of the exploited zero-days on UK organisations. SecurityWeek reports that the September pair hit targets in government, finance, education, legal and professional services, sectors heavily represented in the UK economy. In the US, CISA has catalogued 27 exploited Citrix vulnerabilities since November 2021, seven of them linked to ransomware, BleepingComputer notes. As UK resilience legislation tightens incident reporting expectations, a breach traced back to an unpatched edge device will be difficult to defend.
Expert view
In my experience, the most dangerous phase of a NetScaler advisory is the one we are in now: a critical bug, a vendor saying there is no known exploitation, and a weekend ahead. Memory corruption flaws on this platform have a habit of being reverse engineered from the patch quickly. The high attack complexity rating may slow the less capable crews, but it will not stop the groups that have spent the past year building tooling against these appliances.
The detail I would want every UK administrator to absorb is the build range. Many teams will have closed the September tickets and moved on, reasonably believing their gateway was up to date. If that gateway brokers SAML as an IdP, it is not. When we test perimeter estates, it is common to find SAML features enabled during a past SSO project and never documented, so do not rely on memory: check the configuration.
I would also repeat the NCSC’s broader point from September. With several exploited NetScaler bugs this autumn, any appliance that lagged on earlier patches should be treated as potentially compromised, not merely out of date. Patching closes the door; it does not remove anyone already inside.
What to do now
- Inventory every NetScaler instance, including disaster recovery pairs, lab appliances and Secure Private Access Hybrid components. Cyber Essentials expects you to know what sits on your boundary.
- Check SAML roles on each appliance against the bulletin’s two version bands, so you know which are exposed.
- Upgrade to 14.1-73.46, 13.1-64.29 or the listed FIPS and NDcPP builds. Cyber Essentials Security Update Management requires critical and high-risk fixes within 14 days; for an internet-facing gateway, aim for days, not weeks.
- If you cannot patch immediately, consider restricting management and authentication endpoints to known IP ranges at an upstream firewall, accepting any service impact, in line with Cyber Essentials Firewalls controls.
- Hunt for earlier compromise. Review the indicators Citrix published for CVE-2026-88771 and CVE-2026-88772, check for unexpected files and web shells, and use NetScaler Console File Integrity Monitoring where available.
- Rotate secrets held on or brokered by appliances that were exposed during the September window, including SAML signing certificates and service account credentials.
- Sign up to NCSC Early Warning and Citrix bulletin alerts, and report any suspected compromise to the NCSC.
Bottom line
CVE-2026-107406 is not known to be exploited yet, but NetScaler’s track record this year leaves little room for optimism. If your gateway uses SAML, including those patched only last month, upgrade this weekend, verify the build and look for signs of earlier intrusion.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-107406 (CTX697191)
- BleepingComputer: Citrix warns admins to patch new NetScaler RCE flaw immediately
- SecurityWeek: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
- NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
- NCSC: Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway