Citrix — Critical NetScaler Memory Overflow Flaw Enables RCE in SAML Deployments (CVE-2026-107406)

Publication date: October 09, 2026
Category: Vulnerability / Network Security

Introduction

Citrix has issued security advisories and patches to address a critical vulnerability impacting NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-107406, the vulnerability carries a critical base severity score of 9.5 out of 10.0 according to the CVSS v4.0 framework. The flaw was discovered and responsibly disclosed by Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, alongside Maxim Suhanov. Although there is currently no evidence of active in-the-wild exploitation for this specific flaw, its critical severity mandates prompt remediation by network administrators and security teams.

What is CVE-2026-107406? (General Analysis)

The affected components are NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway, which serve as crucial application delivery controllers, load balancers, and remote access gateways across enterprise networks and hybrid environments (including Secure Private Access deployments).

Conceptually, the vulnerability is a memory overflow flaw that manifests under specific configuration conditions. Specifically, the issue triggers when NetScaler instances are configured either as a SAML Identity Provider (SAML IdP) or as a SAML Service Provider (SAML SP).

  • Official CVSS Vector (CVSS v4.0): AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L — 9.5 (CRITICAL)
  • CWE Classification: Not explicitly reported by NVD, categorized functionally as a memory overflow / buffer management weakness.
  • CISA KEV Catalog: Not listed at this time.

How Does It Work? (Technical Analysis)

Successful exploitation of this vulnerability strictly depends on whether the NetScaler deployment has active SAML configurations. Administrators can verify if their instances match the vulnerable criteria by inspecting their configuration for specific directives:

  • SAML SP: add authentication samlAction
  • SAML IdP: add authentication samlIdPProfile

The technical mechanism behind the vulnerability operates through the following stages:

  • Exploit Entry Vector: An attacker sends maliciously crafted requests to the SAML authentication endpoints managed by the NetScaler ADC or Gateway appliance. Because the authentication flow handles intricate XML/SAML assertion structures and dynamic memory allocation, specially crafted inputs exceed the expected boundaries of internal memory buffers.
  • Unsafe Memory Handling & Code Execution: When the memory overflow occurs within the process space of the targeted service, critical low-level data structures become corrupted. An unauthenticated attacker can leverage this corruption to achieve Remote Code Execution (RCE) with elevated privileges on the device, or trigger a Denial of Service (DoS) condition via application crashes.
  • Hybrid Deployment Context: Hybrid Secure Private Access architectures relying on vulnerable NetScaler instances inherit this exposure if active SAML profiles are present.

Affected Systems / Environments

The impact covers specific versions of NetScaler ADC and NetScaler Gateway, categorized according to their active SAML role:

When configured exclusively as a SAML IdP:

  • NetScaler ADC and NetScaler Gateway between versions 14.1-73.37 and 14.1-73.41, inclusive.
  • NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive.
  • NetScaler ADC and NetScaler Gateway between versions 13.1-64.23 and 13.1-64.28, inclusive.
  • NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1-37.282, inclusive.

When configured as a SAML SP or SAML IdP (prior versions):

  • NetScaler ADC and NetScaler Gateway before 14.1-73.37.
  • NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS.
  • NetScaler ADC and NetScaler Gateway before 13.1-64.23.
  • NetScaler ADC 13.1-FIPS before 13.1-NDcPP 13.1-37.279.
CVE Category (CWE) Impact CVSS Summarized Vector (CVSS v4.0)
CVE-2026-107406 Memory Overflow (Unspecified) RCE / DoS 9.5 (Critical) AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L

Mitigation and Detection

Remediation

The primary and definitive remediation step is to upgrade vulnerable NetScaler instances to the secure firmware versions released by the vendor:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases.
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of branch 13.1.
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS.
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases.

Detection

Incident response and Blue Team operations must audit network topologies immediately to determine whether NetScaler appliances maintain active SAML profiles.

Threat Intelligence Note: The existence of concurrent NetScaler vulnerabilities actively exploited in the wild (such as CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779) amplifies the urgency of executing comprehensive patching schedules and reviewing audit logs for anomalous HTTP/XML request patterns targeting gateway endpoints.

Deploying Deep Packet Inspection (DPI) rules on perimeter firewalls to monitor anomalies in HTTP headers and SAML transactions aimed at authentication nodes is strongly recommended.

Wrapping Up

The identification and timely patching of CVE-2026-107406 emphasize the critical importance of keeping perimeter network infrastructure up to date. As a memory overflow vulnerability capable of enabling remote code execution within SAML deployments, unpatched instances expose corporate gateways to severe compromise. Coordinated disclosure and rapid patching remain the industry’s most effective bulwark against widespread exploitation campaigns.

References