VYPR
patchPublished Oct 9, 2026· 1 source

Citrix NetScaler ADC and Gateway Hit by Critical RCE Vulnerability

Citrix has issued an urgent warning about a critical remote code execution (RCE) vulnerability, CVE-2026-107406, affecting NetScaler ADC and Gateway appliances configured with specific SAML settings.

Citrix has alerted customers to a critical security flaw, identified as CVE-2026-107406, that poses a significant risk to NetScaler ADC and NetScaler Gateway appliances. This memory overflow vulnerability, carrying a CVSS v4.0 score of 9.5, can lead to remote code execution or denial of service if exploited. The vulnerability specifically impacts appliances configured with certain SAML settings, making it crucial for administrators to verify both their software version and authentication configurations.

The security bulletin, CTX697191, details that the issue is classified under CWE-119, indicating improper memory buffer operations. While Citrix stated it was unaware of any unmitigated exploits at the time of the bulletin's release, the potential for exploitation remains high due to the vulnerability's network-based attack vector, requiring no privileges or user interaction, albeit with high attack complexity. The vulnerability was discovered by Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov.

Exposure to CVE-2026-107406 is contingent on the NetScaler's role in SAML-based single sign-on (SSO) configurations. For NetScaler ADC and Gateway versions 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, the vulnerability is present only when the appliance is acting as a SAML Identity Provider (IdP). This condition also applies to specific FIPS and NDcPP builds within these version ranges.

Older supported versions of NetScaler ADC and Gateway, those prior to 14.1-73.37 or 13.1-64.23, are vulnerable regardless of whether they are configured as a SAML Service Provider (SP) or an Identity Provider (IdP). Administrators can identify SAML configurations by checking for the presence of add authentication samlAction (for SP) or add authentication samlIdPProfile (for IdP) entries in their appliance configurations.

Citrix strongly recommends immediate patching to mitigate the risk. For the 14.1 branch, customers should upgrade to version 14.1-73.46 or later. For the 13.1 branch, the recommended fixed version is 13.1-64.29 or later. Specific FIPS and NDcPP builds also have corresponding updated versions available.

This advisory follows a series of recent security updates for NetScaler products, including a previously disclosed SAML zero-day and issues related to appliance reboots after earlier patches. It is critical for administrators to note that patches applied for previous vulnerabilities may not cover CVE-2026-107406, and they must consult CTX697191 for the correct fixed versions specific to this new critical flaw.

Secure Private Access Hybrid deployments that utilize affected NetScaler instances also require these updates. The vendor clarifies that this advisory pertains to customer-managed appliances and not to Citrix-managed cloud services or Adaptive Authentication, which are handled by Citrix directly. Prompt action is advised to protect against potential exploitation.

Synthesized by Vypr AI