Citrix releases fixes for critical NetScaler SAML vulnerability

Citrix has released security updates for CVE-2026-107406, a critical memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway. The flaw has a CVSS score of 9.5 and may lead to remote code execution or denial of service when affected appliances are deployed with specific SAML configurations.
The company said it has no evidence that CVE-2026-107406 has been exploited in the wild. Citrix credited Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, together with Maxim Suhanov, with discovering and reporting the issue.
SAML configuration determines exposure
The vulnerability affects NetScaler instances configured as either a SAML identity provider, or in some cases as a SAML service provider. Citrix said successful exploitation depends on those deployment conditions rather than applying to every NetScaler installation by default.
Administrators can review their configuration for SAML-related entries. The command add authentication samlAction indicates a SAML service-provider configuration, while add authentication samlIdPProfile indicates a SAML identity-provider configuration.
When configured as a SAML identity provider, affected ranges include NetScaler ADC and NetScaler Gateway 14.1-73.37 through 14.1-73.41, as well as 13.1-64.23 through 13.1-64.28. The affected FIPS ranges are 14.1-73.37 FIPS through 14.1-73.41 FIPS and 13.1-NDcPP 13.1-37.279 through 13.1-37.282.
For appliances configured as either a SAML service provider or identity provider, Citrix lists versions before 14.1-73.37, 14.1-FIPS before 14.1-73.37 FIPS, 13.1 before 13.1-64.23, and 13.1-FIPS before 13.1-NDcPP 13.1-37.279 as affected. Secure Private Access Hybrid deployments that use NetScaler instances are also within scope.
Updates supplied by Citrix
Citrix has addressed the issue in NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, and in 13.1-64.29 and later 13.1 releases. The corresponding fixed FIPS versions are 14.1-73.46 FIPS and later, plus 13.1.37.283 and later for NetScaler ADC 13.1-FIPS and 13.1-NDcPP.
The update arrives while three separate NetScaler ADC and NetScaler Gateway flaws—CVE-2026-88771, CVE-2026-88772 and CVE-2026-88779—are under active exploitation in the wild. Citrix did not link those incidents to CVE-2026-107406, but the concurrent activity makes accurate asset and version tracking particularly important.
Practical next steps
Teams should first inventory NetScaler ADC, NetScaler Gateway and Secure Private Access Hybrid instances, then identify which ones use SAML and verify their installed release against Citrix's fixed versions. Prioritising upgrades for SAML-enabled appliances gives security and infrastructure teams a concrete way to address this critical exposure.

