FR
live

Citrix urges patching a NetScaler RCE flaw that hits SAML-configured appliances

On October 9, 2026, Citrix shipped a fix for CVE-2026-107406, a memory-overflow bug that lets an attacker run code remotely or crash NetScaler ADC and Gateway appliances configured as a SAML identity provider or service provider. Upgrade to 14.1-73.46 or 13.1-64.29, or drop the SAML configuration if you do not use it.

An access turnstile in a dark server corridor, a single amber status light glowing on its housing.

October 9, 2026. Citrix ships a fix for CVE-2026-107406, a memory-overflow flaw in NetScaler ADC and NetScaler Gateway. Shadowserver tracks more than 21,000 Citrix appliances exposed to the Internet. September 2026, two NetScaler zero-days were being exploited to steal credentials and drop web shells. The new flaw can run code remotely — and recent history says waiting for the first exploit is the worst possible strategy.

One memory flaw, two outcomes

CVE-2026-107406 is a memory overflow weakness. In practice, an attacker who sends a crafted request to a vulnerable appliance gets one of two results: remote code execution (RCE) — full control of the box — or a denial of service that crashes the process and forces a reboot. The second outcome is the milder one, but on a remote-access gateway a forced crash is already an access outage for an entire organization.

The decisive detail is a condition: to be vulnerable, the appliance must be configured as a SAML identity provider (IdP) or service provider (SP). That is exactly the configuration that carries single sign-on for thousands of companies — the ones federating identities to Microsoft Entra, Okta or Google Workspace through NetScaler are precisely the ones with an active SAML surface.

Citrix is blunt about it: “We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.” At the time of publication, the vendor knew of no exploitation of the flaw. That is a window, not a guarantee.

The real blast radius comes down to SAML

The question every team has to answer is a single sentence: do my NetScaler appliances federate SAML? If the answer is yes, the fix is a priority. If it is no, the flaw does not apply — but you have to check every instance, because an IdP configuration inherited from an old project can linger on a gateway nobody has looked at in months.

Shadowserver’s numbers give the scale of the exposure. The monitoring service tracks more than 21,000 IP addresses carrying a NetScaler fingerprint on the Internet, including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances. How many are honeypots, already patched, or vulnerable in this specific configuration? Shadowserver does not say. But the order of magnitude is enough: the window between an advisory and the first exploit has already closed in days on similar products.

The exposure is all the more serious because NetScaler Gateway is, by nature, Internet-facing. A remote-access gateway is a perimeter, not an internal box. An RCE on this kind of appliance needs no prior lateral movement: the attacker is already at the door.

The fixed versions, branch by branch

Citrix fixed the flaw in two main branches, with FIPS and NDcPP variants not to be forgotten.

  • NetScaler ADC and NetScaler Gateway 14.1-73.46 and later.
  • NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1.
  • NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP.

The presence of the FIPS and NDcPP variants is not a footnote: these are the releases deployed in regulated environments — government and critical sectors — where validation cycles slow the upgrade. If you run a FIPS branch, the fixed version is a distinct number; do not copy the standard-branch version.

The right move is to run Citrix’s version-check tool to confirm the exact fixed release for your train, then schedule the upgrade with the reboot window it requires.

NetScaler’s history makes waiting a bad bet

The temptation to defer is real: no known exploitation, no public proof of concept, a flaw conditional on a SAML configuration. But NetScaler’s recent history argues against waiting.

In March 2026, Citrix was already asking customers to patch two flaws (CVE-2026-3055 and CVE-2026-4368); threat actors exploited them days later. In September 2026, the vendor shipped fixes for two actively exploited RCE zero-days, CVE-2026-88771 and CVE-2026-88772, which let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access, and move into victims’ internal networks. Earlier this month, an emergency update closed CVE-2026-88779, a denial-of-service zero-day that researchers later judged also exploitable for RCE.

The CISA catalog confirms the trend: 27 actively exploited Citrix vulnerabilities have been listed since November 2021, including seven used in ransomware campaigns. Remote-access appliances are a prime target for financially motivated groups, who use them as the initial foothold before deploying their encryptor.

The advisory itself nudges toward the same conclusion. Citrix’s guidance is blunt about the fix path — upgrade, and if you cannot upgrade immediately, review whether the SAML surface can be temporarily reduced. For an appliance whose entire job is to sit at the authentication edge, there is no low-effort mitigation, and every hour of delay is an hour an attacker can spend finding you first.

Three checks to verify your exposure

The flaw is conditional on a SAML configuration, which makes verification fast if you know where to look.

First, the version. Every NetScaler appliance shows its version in the management interface — a quick read is enough to compare against the fixed list. Citrix’s version-check tool does this automatically, but the version alone is not the whole story: an appliance up to date in its standard branch can hide a FIPS or NDcPP instance lagging behind.

Second, the SAML configuration. The question is not “do we have SAML enabled?” but “where?”. An organization federating identities to an identity provider often has several entry points — a Gateway for remote access, an ADC appliance for an internal application — and a forgotten IdP configuration on any one of them is enough to be exposed.

Third, Internet exposure. Shadowserver’s portal lets you check whether your addresses appear among the NetScaler appliances it tracks. It is a free check that answers the simplest question: am I visible, or not?

These three checks take under an hour — which is exactly how long an attacker watching Citrix advisories will take to start scanning.

Verdict

If your NetScaler ADC or Gateway appliances carry a SAML IdP or SP configuration, treat CVE-2026-107406 as a priority for the week: a crafted request can hand control of an Internet-facing box, and the NetScaler zero-day precedent shows the window before exploitation is measured in days, not months. Patch now to 14.1-73.46 or 13.1-64.29 depending on your branch — and if a FIPS or NDcPP build is running somewhere, cover it too. If you do not use SAML on your NetScaler fleet, the flaw does not apply to you, but use the moment to audit your gateway exposure: a forgotten IdP configuration is exactly the kind of surface an attacker finds before you do. In every case, do not let the absence of known exploitation become a reason to wait — that is precisely the reasoning ransomware campaigns like to see drag on.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

FakeGit re-arms 17,610 malicious GitHub repos to drop SmartLoader and steal sessions

On October 8, 2026, Apiiro revealed that the FakeGit campaign has re-activated 17,610 fake GitHub repositories distributing the SmartLoader loader, several hundred of them impersonating AI skills and MCP servers. Before installing a repo from GitHub, check the account owner and prefer official registries.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss