CVE-2026-107406 affects SAML IdP and SP configurations, and three other NetScaler bugs are already being exploited
Citrix has shipped emergency patches for a critical memory overflow in NetScaler ADC and NetScaler Gateway. Under specific configurations, it allows unauthenticated remote code execution (RCE) or denial of service (DoS). The flaw is tracked as CVE-2026-107406 and scores 9.5 out of 10.0 on CVSS v3.1. It sits in the SAML authentication processing path, which in many enterprises fronts access to thousands of internal applications and cloud services.
The timing is bad for NetScaler admins. CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 are all under confirmed active exploitation, so teams are triaging a patched critical RCE vector while neighboring flaws are being abused in the wild.
What is CVE-2026-107406
CVE-2026-107406 is a memory overflow in how NetScaler ADC and Gateway process SAML (Security Assertion Markup Language) authentication messages. A crafted or malformed SAML assertion can corrupt adjacent memory. That lets an attacker either hijack the NetScaler process for arbitrary code execution or crash the service.
Citrix’s advisory says the issue “may lead to remote code execution or denial-of-service under specific configuration conditions.” The condition is SAML being configured, and SAML single sign-on through NetScaler is common in large enterprises, so plenty of deployments meet it.
Citrix reports no in-the-wild exploitation of CVE-2026-107406 so far. NetScaler bugs have a record of being weaponized within days of disclosure, and three sibling CVEs are being exploited right now. I would plan around hours, not weeks.
Which configurations are exposed
Exposure depends on whether the appliance is set up as a SAML Identity Provider (IdP) or a SAML Service Provider (SP). With neither role configured, the vulnerable code path is unreachable and the appliance is not exposed to this CVE.
To check, look in the CLI or the GUI configuration tree for these entries:
add authentication samlActionmeans the appliance is a SAML SP and relies on an external IdP to authenticate users before granting access to backend resources.add authentication samlIdPProfilemeans the appliance issues SAML assertions itself and acts as the IdP for downstream service providers.
If either exists in the running configuration, the deployment is in scope. If neither does, CVE-2026-107406 does not apply to that instance, but CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 still need their own assessment.
SAML is an XML framework for passing authentication and authorization data between parties. When a NetScaler acts as an SP, an unauthenticated user hitting a protected application gets redirected to an external IdP such as Microsoft Entra ID, Okta, or ADFS. The IdP authenticates the user and returns a signed assertion, which the NetScaler validates before granting access. Parsing that XML, verifying the signature, and extracting attributes is where the overflow lives. Oversized attributes, malformed XML, or manipulated signature blocks are the obvious ways to reach it. When the NetScaler is the IdP, the same parsing and serialization routines handle incoming authentication requests, so the same overflow applies.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Affected versions
Citrix segmented the affected builds by SAML role and product line.
Affected when configured as a SAML IdP
| Product | Affected version range |
|---|---|
| NetScaler ADC & NetScaler Gateway | 14.1-73.37 through 14.1-73.41 (inclusive) |
| NetScaler ADC 14.1-FIPS | 14.1-73.37 FIPS through 14.1-73.41 FIPS (inclusive) |
| NetScaler ADC & NetScaler Gateway | 13.1-64.23 through 13.1-64.28 (inclusive) |
| NetScaler ADC 13.1-FIPS / 13.1-NDcPP | 13.1-37.279 through 13.1-37.282 (inclusive) |
Affected when configured as a SAML SP or SAML IdP
| Product | Affected versions |
|---|---|
| NetScaler ADC & NetScaler Gateway | All builds before 14.1-73.37 |
| NetScaler ADC 14.1-FIPS | All builds before 14.1-73.37 FIPS |
| NetScaler ADC & NetScaler Gateway | All builds before 13.1-64.23 |
| NetScaler ADC 13.1-FIPS / 13.1-NDcPP | All builds before 13.1-37.279 |
Citrix also says Secure Private Access Hybrid deployments that include NetScaler instances are in scope. In a hybrid setup, every NetScaler node in the chain needs the upgrade, including nodes behind the primary edge pair.
Fixed versions
| Product | Fixed version |
|---|---|
| NetScaler ADC & NetScaler Gateway | 14.1-73.46 and later |
| NetScaler ADC & NetScaler Gateway (13.1 branch) | 13.1-64.29 and later |
| NetScaler ADC 14.1-FIPS | 14.1-73.46 FIPS and later |
| NetScaler ADC 13.1-FIPS / 13.1-NDcPP | 13.1-37.283 and later |
There is no workaround. Citrix has published no configuration change that neutralizes the overflow, so the only real remediation is a firmware upgrade. If an upgrade window is impossible right now, restrict access to the management interface and SAML endpoints to trusted IP ranges with ACLs or upstream firewall rules. That reduces exposure without removing it, so treat it as a stopgap until you can patch.
Credit and disclosure
Citrix credited four researchers: Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, and independent researcher Maxim Suhanov.
Citrix has not released a technical write-up, proof-of-concept code, or a root-cause analysis, so the affected function and buffer are unknown. That is normal in the first patch window, since vendors want defenders to have a head start before researchers reverse the fix. Expect public analysis within days to weeks.
Three NetScaler CVEs already under active exploitation
Citrix confirmed that CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 are being exploited in real attacks. The technical details and exploitation chains for those three are outside this advisory, but their active abuse raises the urgency for anyone running NetScaler ADC or Gateway.
NetScaler appliances sit at the network edge, often exposed directly to the internet, terminating TLS, brokering authentication, and load-balancing critical applications. Nation-state groups and ransomware affiliates both go after them. A compromised appliance can give an attacker:
- routes into internal networks, since the device typically reaches multiple backend segments
- credentials, particularly when SAML, OAuth, or LDAP authentication passes through it
- persistent access, through backdoors at the firmware or configuration level that survive reboots
- SSL/TLS keys, which allow decryption of intercepted traffic
The history backs this up. CVE-2019-19781, a critical path traversal flaw, was exploited within 48 hours of disclosure in 2020 and went on to affect an estimated 80,000+ appliances worldwide. In 2023, CVE-2023-3519 was exploited as a zero-day to drop web shells on unpatched appliances, and Citrix later confirmed thousands of devices were compromised before the patch was widely applied.
Why memory bugs in SAML parsing are dangerous
SAML assertions are XML documents that can hold nested elements, base64-encoded certificates, XMLDSig signatures, attribute statements, and conditions. To handle them, the firmware has to allocate buffers, validate the schema, verify signatures, and extract user attributes. That code is typically written in C or C++ for performance on dedicated hardware.
Citrix has not said which kind of overflow this is, so what follows is general. A stack overflow during attribute extraction could overwrite a return address and redirect execution to attacker-controlled code. A heap overflow during XML deserialization could corrupt heap metadata and give a write-what-where primitive, which can overwrite function pointers or vtable entries. Either way, the goal is code execution inside the NetScaler process, which on these appliances usually runs with elevated privileges because of its role in traffic management and encryption.
Signed and sometimes encrypted tasks add another layer. The pipeline has to run RSA or ECDSA signature verification and AES decryption alongside XML parsing. An assertion that passes the first structural checks but carries edge-case data in its cryptographic fields, such as oversized key material, unexpected padding, or a malformed certificate chain, can trigger odd buffer allocations or wrong length calculations further down.
This is also why the bug is limited to SAML deployments. The vulnerable routines are in the firmware of every appliance, but they are only reachable once a samlAction or samlIdPProfile object is defined and bound to an authentication policy.
What to do now
- Inventory every NetScaler ADC and Gateway appliance: primary data center pairs, DR instances, cloud-hosted VPX instances, and anything inside Secure Private Access Hybrid architectures. Asset databases go stale, so also query the network for NetScaler management interfaces on TCP 22 (SSH), TCP 443 (GUI), and any custom management ports.
- Check each appliance’s SAML configuration by running
show authentication samlActionandshow authentication samlIdPProfilein the CLI. If either returns objects, the appliance is in scope. Write down what you find. - Compare firmware versions against the affected ranges above. Anything inside a range, or older than the fixed builds, goes to the front of the queue.
- Upgrade to at least 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283 NDcPP, depending on your product line and branch. Follow Citrix’s upgrade documentation, take the pre-upgrade backups (
save ns config, plus backups of the/nsconfigand/varpartitions), and test in staging if you can. - Deal with CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779 at the same time. They are under active exploitation, so if your appliances are not already patched against them, run this as incident response. Read Citrix’s separate advisories, apply the fixes, and start a compromise assessment: look for unexpected configuration changes, unknown admin accounts, odd SSL certificates, unexpected processes, and web shells on the NetScaler file system.
- Forward authentication events, SAML assertion processing logs, and system audit logs to your SIEM. Watch for repeated failed assertions from a single source IP, assertions with unusual attribute sizes, authentication spikes outside business hours, and configuration changes with no approved ticket behind them.
- Until patching is done, limit access to the NetScaler management IP (NSIP) and, where the architecture allows, restrict SAML endpoint URLs to known IdP or SP partner ranges using NetScaler ACLs or upstream firewall rules.
- Tell application owners and the help desk about the upgrade window, since a NetScaler reboot briefly interrupts traffic. Pick the lowest-traffic period. On an HA pair, upgrade the secondary first, validate, fail over, then upgrade the former primary.
A recurring NetScaler problem
NetScaler handles HTTP/S, TLS termination, SAML, OAuth, LDAP, RADIUS, DNS, and load-balancing logic in one firmware image. Every protocol parser, authentication module, and cryptographic handler in that image is a possible home for memory safety bugs, logic flaws, or injection vulnerabilities. F5 BIG-IP, Fortinet FortiGate, and other edge appliances share the problem. NetScaler’s weight in enterprise SSO and application delivery means one critical CVE can hit tens of thousands of organizations at once. The XOR Team’s find also shows that well-resourced enterprises are turning up these bugs through their own internal research.
If you are reviewing your architecture, consider moving SAML authentication to a dedicated or cloud-based IdP so the edge appliance parses less. Any software that processes authentication assertions can have bugs, but this puts less critical authentication logic on one perimeter device.
Bottom line
A 9.5-rated memory overflow in SAML processing, on a perimeter device, with no workaround and three sibling CVEs already exploited, is a patch-now situation. That Citrix has not reported exploitation of CVE-2026-107406 itself is a short window, and I would not use it as a reason to push the upgrade down the list. Verify your SAML configuration, confirm your firmware version, and schedule the upgrade.
This article will be updated if Citrix releases further technical details, proof-of-concept information, or revised guidance. Citrix’s official security bulletins are on the Citrix Support portal, and CISA’s Known Exploited Vulnerabilities catalog tracks exploitation.









