Citrix is urging NetScaler customers to install updated builds for CVE-2026-107406, a memory overflow vulnerability that can result in remote code execution or denial of service.
The flaw affects NetScaler ADC and NetScaler Gateway appliances running particular versions and configured for Security Assertion Markup Language functions. Whether an appliance is vulnerable depends on both its build and whether it operates as a SAML Identity Provider (IdP) or Service Provider (SP).
A report published on October 9, 2026 described the issue as critical and relayed Citrix’s recommendation to upgrade affected systems as soon as possible. The date of the underlying Citrix bulletin was not specified.
Citrix said it had found no evidence of exploitation in the wild and was unaware of any “unmitigated exploits” when its bulletin was published. Those are company statements rather than independently confirmed findings.
Exposure changes according to the SAML role and installed build
The NVD description identifies CVE-2026-107406 as a memory overflow affecting NetScaler ADC and NetScaler Gateway. Exploitation could allow code execution on the targeted appliance or cause a denial-of-service condition and crashes.
The configuration requirements are not identical across all affected releases.
For the following older builds, the vulnerability applies when an appliance is configured as either a SAML SP or SAML IdP:
- NetScaler ADC and NetScaler Gateway before 14.1-73.37
- NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
- NetScaler ADC and NetScaler Gateway before 13.1-64.23
- NetScaler ADC 13.1-FIPS before 13.1-NDcPP 13.1-37.279, following the wording in the available NVD description
Several later intervals are described as vulnerable only when the appliance operates as a SAML IdP:
- NetScaler ADC and NetScaler Gateway from 14.1-73.37 through 14.1-73.41, inclusive
- NetScaler ADC 14.1-FIPS from 14.1-73.37 FIPS through 14.1-73.41 FIPS, inclusive
- NetScaler ADC and NetScaler Gateway from 13.1-64.23 through 13.1-64.28, inclusive
- NetScaler ADC 13.1-FIPS from 13.1-NDcPP 13.1-37.279 through 13.1- 37.282, inclusive, as rendered in the supplied NVD text
The final entry combines product and version labels in an unusual way. It is reproduced without normalizing the boundary because doing so could change its meaning.
No CVSS score, vector, or CWE classification for CVE-2026-107406 is available in the cited records. Consequently, “critical” remains the news report’s characterization rather than a severity rating confirmed from the available NVD data.
Citrix’s reported upgrade targets
Citrix’s reported instruction is to review its advisory and move affected NetScaler systems to the recommended versions. The listed upgrade destinations are:
- NetScaler ADC and NetScaler Gateway 14.1-73.46 and later
- NetScaler ADC and NetScaler Gateway 13.1-64.29 and later in the 13.1 branch
- NetScaler ADC 14.1-73.46 FIPS and later in the 14.1-FIPS branch
- NetScaler ADC 13.1.37.283 and later in the 13.1-FIPS and 13.1-NDcPP branches
These targets come from reporting that attributes them to Citrix. The vendor advisory itself was not available for comparison.
Administrators should first identify the exact build on every NetScaler ADC and Gateway appliance, then establish whether each system provides SAML IdP or SP services. An inventory containing only product names will not determine exposure because the applicable configuration condition changes at specific build boundaries.
Internet accessibility also does not establish vulnerability. Shadowserver reportedly tracks more than 21,000 internet-exposed IP addresses with NetScaler fingerprints, including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances.
The date of that count was not given. It also does not indicate how many addresses represent honeypots, patched devices, or systems configured for affected SAML roles, so it cannot be treated as a vulnerable-device total.
Recent NetScaler flaws have already reached the KEV catalog
CVE-2026-107406 follows several NetScaler vulnerabilities connected to reported exploitation during 2026.
In March, Citrix urged customers to patch CVE-2026-3055 and CVE-2026-4368. The October 9 report says attackers began abusing them days after that warning.
CVE-2026-3055 is a CWE-125 out-of-bounds read caused by inadequate input validation when NetScaler operates as a SAML IdP. Its CVSS 3.1 score is 9.8, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-30 and set 2026-04-02 as the remediation deadline for US federal agencies.
CVE-2026-4368 is a CWE-362 race condition. It can produce a user session mix-up on appliances configured as a Gateway—SSL VPN, ICA Proxy, CVPN, or RDP Proxy—or as an AAA virtual server.
Citrix released updates in September for CVE-2026-88771 and CVE-2026-88772, both reported as actively exploited zero-days. CISA placed both in KEV on 2026-09-27, with federal remediation due 2026-09-30.
CVE-2026-88771 has a 9.8 CVSS score and can allow an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 carries an 8.1 score and can lead to remote code execution or denial of service. Reporting on the associated attacks described web shells, tunneling malware, credential theft, root access and movement into internal networks; those post-exploitation details are not part of the cited NVD records.
Earlier in October, Citrix issued emergency updates for CVE-2026-88779. CISA added it to KEV on 2026-10-04 and gave federal agencies until 2026-10-07 to remediate it.
CVE-2026-88779 has a 7.5 CVSS score and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, which records availability impact without confidentiality or integrity impact. Researchers and administrators reportedly said the flaw could also support remote code execution, but that claim is not confirmed by the cited vector.
Two other Citrix vulnerabilities entered KEV within the preceding 90 days: CVE-2026-8452 on 2026-08-26 and CVE-2026-19490 on 2026-09-09.
KEV requirements apply to the earlier exploited vulnerabilities
The available records do not establish a KEV entry for CVE-2026-107406. That limited result should not be interpreted as proof that the vulnerability is absent from the complete catalog.
For CVE-2026-3055, CISA required federal agencies to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue using the product if mitigations were unavailable.
For CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779, CISA required vendor-directed mitigations, compliance with BOD 26-04 Prioritizing Security Updates Based on Risk and its Forensics Triage Requirements. The direction also requires applicable BOD 26-04 treatment for cloud services or discontinuing the product if mitigations are unavailable, along with evaluation of each asset’s internet exposure.
Those prescriptions and deadlines apply to US federal agencies. CISA’s inclusion of the earlier CVEs in KEV establishes known exploitation of those specific vulnerabilities, not of CVE-2026-107406.
The October 9 report separately states that CISA has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven used in ransomware attacks. That aggregate was not independently checked against the complete catalog.
Immediate checks for NetScaler operators
Organizations running NetScaler ADC or Gateway should map every appliance to its exact version and SAML role. Systems falling within the applicable IdP or SP conditions should be upgraded to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1.37.283, according to their branch.
Teams should also verify that remediation for the earlier KEV-listed NetScaler vulnerabilities is complete. Their confirmed exploitation and expired federal deadlines are separate from Citrix’s current statement that it has not observed CVE-2026-107406 attacks.
For the newly reported flaw, the supported operational instruction is straightforward: identify affected SAML-enabled appliances and apply Citrix’s recommended upgrade.




