Skip to content

Security2 publishersIndependently confirmed2 min readPublished

SAML role decides which NetScaler appliances Citrix's new RCE flaw can reach

Citrix urged NetScaler customers to patch CVE-2026-107406, a memory overflow that allows remote code execution on appliances set up as SAML IdP or SP. The company says it knows of no attacks so far, on a product line where it has patched exploited zero-days twice in recent weeks.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying SAML role decides which NetScaler appliances Citrix's new RCE flaw can reach
Generated illustration

What happened

  • SecurityWeek reports a CVSS score of 9.5, and the same overflow can be used for denial of service as well as code execution.
  • Fixed builds are 14.1-73.46 and 13.1-64.29 for ADC and Gateway, 14.1-73.46 FIPS, and 13.1.37.283 for the 13.1-FIPS and 13.1-NDcPP releases.
  • Secure Private Access Hybrid deployments that use NetScaler are also affected and need the same upgrade, according to SecurityWeek.
  • Shadowserver tracks more than 21,000 IP addresses on the internet showing NetScaler fingerprints.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Admins can sort a NetScaler fleet by one setting, the SAML IdP or SP role, and move those appliances to the fixed builds first.
  • constraint Internet scan counts cannot show which exposed boxes are honeypots, already patched or SAML-configured, so sizing exposure depends on each operator's own configuration inventory.
  • precedent CISA has listed 27 Citrix flaws as exploited since November 2021, seven of them in ransomware attacks. On that record, Citrix's current no-known-exploitation status is best treated as temporary.

The SAML role is a necessary condition. Citrix says an ADC or Gateway appliance has to be configured as a SAML Identity Provider or Service Provider to be vulnerable [3]. SecurityWeek's summary of the advisory narrows it further, to SAML appliances "under specific configuration conditions" [4]. Neither report lists those conditions. Until an appliance with a SAML role has been checked against the advisory text or upgraded, it belongs on the exposed list.

Shadowserver's numbers do not narrow the field. Its count splits into just over 1,500 Gateway instances and nearly 20,000 ADC appliances [15]. ADC boxes are more than nine in ten of the exposed fingerprints [18]. Both product lines are vulnerable when they hold a SAML role [3].

On exploitation, the public record is the vendor's statement. "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability," the company said in the bulletin it issued Thursday [6] [11]. "We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible," Citrix said [5].

The NetScaler bugs before this one were used in attacks. Citrix patched two zero-days in September, CVE-2026-88771 and CVE-2026-88772. According to BleepingComputer, they let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access and spread into internal networks [8]. SecurityWeek reported they were used against government, financial services, education, legal and professional services organizations [10]. BleepingComputer also counts CVE-2026-3055 and CVE-2026-4368, patched in March, among the NetScaler flaws attackers have abused this year [17].

Citrix shipped emergency updates earlier this month for CVE-2026-88779, a zero-day it described as denial of service. Researchers and admins later said that flaw could also be exploited for remote code execution, BleepingComputer reported [9]. The code-execution claim came from outside Citrix. For CVE-2026-107406, the advisory lists code execution as a possible outcome from the start [1].

What to watch

  • Whether Citrix revises its exploitation statement or CISA adds CVE-2026-107406 to its exploited-vulnerabilities list.
  • Publication of technical analysis or proof-of-concept code for the memory overflow.
  • Whether Shadowserver starts reporting how many exposed NetScaler hosts remain unpatched or run a SAML role.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption55
Hype gap+5
Incentives
Insufficient
Confidence70
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Citrix warned administrators to patch immediately against CVE-2026-107406, a memory overflow weakness in NetScaler ADC and NetScaler Gateway that attackers can exploit to gain remote code execution or trigger a denial-of-service state.

  2. [2]

    CVE-2026-107406 has a CVSS score of 9.5 and is described as a memory overflow that could lead to remote code execution or denial of service.

  3. [3]

    To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a SAML Identity Provider (IdP) or Service Provider (SP).

Sources

2 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 9, 2026

    Citrix warns admins to patch new NetScaler RCE flaw immediately
  2. securityweek.com

    1 article · October 8, 2026

    Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories