CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability

CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability

SOC Prime Team
SOC Prime Team linkedin icon Follow

Citrix has disclosed CVE-2026-107406, a critical memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances configured for specific SAML authentication roles. The flaw carries a CVSS v4.0 score of 9.5 and could enable an unauthenticated remote attacker to execute arbitrary code or trigger a denial-of-service condition on vulnerable systems.

The vulnerability is particularly significant because NetScaler appliances frequently operate at the network perimeter and provide authentication, application delivery, and remote-access functionality. Successful exploitation could therefore compromise infrastructure positioned between external users and sensitive enterprise resources.

Citrix published security bulletin CTX697191 on October 8, 2026, urging affected organizations to upgrade immediately. Exposure depends not only on the installed NetScaler build but also on whether the appliance is configured as a SAML service provider (SP) or identity provider (IdP). Citrix stated at disclosure that it was not aware of unmitigated exploits targeting the flaw.

Organizations can strengthen their defenses against emerging vulnerability exploitation with SOC Prime’s AI-Native Detection Intelligence Platform, which helps security teams accelerate threat detection engineering, threat hunting, and investigation across diverse security environments.

Security professionals can also use Prime Architect and Uncoder AI capabilities to transform threat intelligence into detection logic, generate hunting queries, adapt detections to organizational telemetry, and translate rules across supported SIEM, EDR, XDR, and Data Lake technologies.

Contact Sales

CVE-2026-107406 Analysis

CVE-2026-107406 affects customer-managed NetScaler ADC and NetScaler Gateway appliances running vulnerable versions and configured with applicable SAML functionality. Citrix describes the issue as a memory overflow vulnerability that can result in remote code execution or denial of service. It is classified under CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer.

The CVSS vector indicates that exploitation can occur remotely over the network without authentication or user interaction. However, Citrix rates attack complexity as high, suggesting that successful exploitation requires specific technical conditions beyond simply reaching a vulnerable appliance.

The exact exposure conditions vary according to software build. NetScaler ADC and Gateway releases between 14.1-73.37 and 14.1-73.41, inclusive, and versions between 13.1-64.23 and 13.1-64.28, inclusive, are vulnerable when configured as a SAML IdP. Equivalent affected ranges also exist for NetScaler ADC 14.1-FIPS and 13.1-FIPS/NDcPP deployments.

Older supported releases have broader exposure. Builds earlier than 14.1-73.37 or 13.1-64.23 can be vulnerable when configured as either a SAML SP or SAML IdP. Administrators therefore need to evaluate both the appliance version and authentication configuration rather than relying solely on version information.

Citrix recommends checking NetScaler configurations for add authentication samlAction, which indicates a SAML SP configuration, and add authentication samlIdPProfile, which identifies a SAML IdP configuration. These entries should then be correlated with the applicable vulnerable build ranges.

Secure Private Access Hybrid deployments that use affected NetScaler instances are also exposed and require upgrades. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are handled separately because Cloud Software Group applies the necessary software updates to those managed environments.

The flaw was reported through coordinated vulnerability disclosure, with Citrix crediting Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, as well as Maxim Suhanov. The vendor has not publicly disclosed the exact date on which the vulnerability was initially discovered.

At the time of publication, neither Citrix nor the referenced reporting identifies a publicly available CVE-2026-107406 PoC or a confirmed real-world exploitation campaign. Nevertheless, the vulnerability’s critical severity, network accessibility, and potential for unauthenticated code execution make rapid remediation a priority.

For CVE-2026-107406 detection, security teams should first identify exposed appliances by correlating NetScaler versions with SAML SP and IdP configurations. Defenders should also review NetScaler telemetry for unexpected service instability, crashes, abnormal network activity, or other behavior that could indicate attempts to exploit memory corruption.

CVE-2026-107406 Mitigation

Citrix strongly recommends upgrading affected NetScaler appliances as soon as possible. The vendor has released patched builds covering the supported product branches.

  • NetScaler ADC and NetScaler Gateway 14.1: upgrade to 14.1-73.46 or later; NetScaler ADC and Gateway 13.1: upgrade to 13.1-64.29 or later; NetScaler ADC 14.1-FIPS: upgrade to 14.1-73.46 FIPS or later; NetScaler ADC 13.1-FIPS and 13.1-NDcPP: upgrade to 13.1-37.283 or later.

Organizations operating Secure Private Access Hybrid deployments should also ensure that the underlying NetScaler instances are updated to the relevant fixed releases. Appliances that have reached end of life should be migrated to supported versions rather than left exposed on outdated builds.

Administrators can use NetScaler Console Security Advisory functionality to identify impacted instances through a version scan and initiate the recommended upgrade workflow. This can help organizations assess multiple NetScaler appliances and prioritize vulnerable systems for remediation.

To Detect CVE-2026-107406 exposure, security teams should inventory internet-facing NetScaler systems, determine their exact builds, and verify whether each appliance is operating as a SAML SP, SAML IdP, or both. Because the vendor has not disclosed exploitation-specific CVE-2026-107406 IOCs, defenders should avoid relying solely on static indicators and instead combine vulnerability exposure management with behavioral monitoring.

Security teams should also examine suspicious activity surrounding affected appliances and correlate NetScaler events with firewall, identity, endpoint, and network telemetry. Any unexpected service crashes or abnormal activity involving externally accessible SAML endpoints should receive additional investigation until affected instances have been upgraded.

SOC Prime’s AI-Native Detection Intelligence Platform can help organizations operationalize emerging threat intelligence, accelerate detection engineering, and improve visibility into potential vulnerability exploitation across their security infrastructure.

FAQ

What is CVE-2026-107406 and how does it work?

CVE-2026-107406 is a critical memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway. An unauthenticated remote attacker may be able to trigger memory corruption that results in arbitrary code execution or denial of service. Exploitation depends on the affected software version and whether the appliance is configured as a SAML SP or SAML IdP.

When was CVE-2026-107406 first discovered?

Citrix has not published the precise initial discovery date. The vulnerability was publicly disclosed through security bulletin CTX697191 on October 8, 2026. Citrix credited researchers from the JPMorgan Chase XOR Team and Maxim Suhanov for responsibly working with the vendor on the issue.

What is the impact of CVE-2026-107406 on systems?

Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on a vulnerable NetScaler appliance or cause a denial of service. Because these systems frequently provide internet-facing application delivery and authentication services, compromise could create significant security risks for connected enterprise infrastructure.

Can CVE-2026-107406 still affect me in 2026?

Yes. Customer-managed NetScaler ADC and Gateway appliances running affected builds remain exposed if they meet the relevant SAML configuration preconditions and have not been upgraded. Citrix-managed cloud services receive the necessary updates directly from Cloud Software Group.

How can I protect myself from CVE-2026-107406?

Upgrade affected NetScaler ADC and Gateway appliances to the vendor-recommended fixed builds immediately. Verify both software versions and SAML configurations, prioritize externally accessible systems, and investigate anomalous appliance behavior. Administrators should continue monitoring Citrix’s security bulletin for updated details for CVE-2026-107406.

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.

More CVEs Articles