Security2 publishersIndependently confirmed2 min readPublished
SAML role decides which NetScaler appliances Citrix's new RCE flaw can reach
Citrix urged NetScaler customers to patch CVE-2026-107406, a memory overflow that allows remote code execution on appliances set up as SAML IdP or SP. The company says it knows of no attacks so far, on a product line where it has patched exploited zero-days twice in recent weeks.
The Watch · Security desk

What happened
- SecurityWeek reports a CVSS score of 9.5, and the same overflow can be used for denial of service as well as code execution.
- Fixed builds are 14.1-73.46 and 13.1-64.29 for ADC and Gateway, 14.1-73.46 FIPS, and 13.1.37.283 for the 13.1-FIPS and 13.1-NDcPP releases.
- Secure Private Access Hybrid deployments that use NetScaler are also affected and need the same upgrade, according to SecurityWeek.
- Shadowserver tracks more than 21,000 IP addresses on the internet showing NetScaler fingerprints.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Admins can sort a NetScaler fleet by one setting, the SAML IdP or SP role, and move those appliances to the fixed builds first.
- constraint Internet scan counts cannot show which exposed boxes are honeypots, already patched or SAML-configured, so sizing exposure depends on each operator's own configuration inventory.
- precedent CISA has listed 27 Citrix flaws as exploited since November 2021, seven of them in ransomware attacks. On that record, Citrix's current no-known-exploitation status is best treated as temporary.
The SAML role is a necessary condition. Citrix says an ADC or Gateway appliance has to be configured as a SAML Identity Provider or Service Provider to be vulnerable [3]. SecurityWeek's summary of the advisory narrows it further, to SAML appliances "under specific configuration conditions" [4]. Neither report lists those conditions. Until an appliance with a SAML role has been checked against the advisory text or upgraded, it belongs on the exposed list.
Shadowserver's numbers do not narrow the field. Its count splits into just over 1,500 Gateway instances and nearly 20,000 ADC appliances [15]. ADC boxes are more than nine in ten of the exposed fingerprints [18]. Both product lines are vulnerable when they hold a SAML role [3].
On exploitation, the public record is the vendor's statement. "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability," the company said in the bulletin it issued Thursday [6] [11]. "We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible," Citrix said [5].
The NetScaler bugs before this one were used in attacks. Citrix patched two zero-days in September, CVE-2026-88771 and CVE-2026-88772. According to BleepingComputer, they let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access and spread into internal networks [8]. SecurityWeek reported they were used against government, financial services, education, legal and professional services organizations [10]. BleepingComputer also counts CVE-2026-3055 and CVE-2026-4368, patched in March, among the NetScaler flaws attackers have abused this year [17].
Citrix shipped emergency updates earlier this month for CVE-2026-88779, a zero-day it described as denial of service. Researchers and admins later said that flaw could also be exploited for remote code execution, BleepingComputer reported [9]. The code-execution claim came from outside Citrix. For CVE-2026-107406, the advisory lists code execution as a possible outcome from the start [1].
What to watch
- Whether Citrix revises its exploitation statement or CISA adds CVE-2026-107406 to its exploited-vulnerabilities list.
- Publication of technical analysis or proof-of-concept code for the memory overflow.
- Whether Shadowserver starts reporting how many exposed NetScaler hosts remain unpatched or run a SAML role.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Citrix warned administrators to patch immediately against CVE-2026-107406, a memory overflow weakness in NetScaler ADC and NetScaler Gateway that attackers can exploit to gain remote code execution or trigger a denial-of-service state.
- [2]
CVE-2026-107406 has a CVSS score of 9.5 and is described as a memory overflow that could lead to remote code execution or denial of service.
- [3]
To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a SAML Identity Provider (IdP) or Service Provider (SP).
- [4]
According to Citrix, the defect impacts NetScaler ADC and Gateway appliances configured as a SAML SP or SAML IdP, "under specific configuration conditions."
ReportedSupportedSource: SecurityWeek, summarizing Citrix2 sources— create a free account to open themView cited source - [5]
"We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible,"
- [6]
"As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability."
- [7]
Fixed versions: NetScaler ADC and Gateway 14.1-73.46 and later; 13.1-64.29 and later releases of 13.1; NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later; 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later.
- [8]
In September, Citrix released security updates for two actively exploited NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772, that let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access, and spread into victims' internal networks.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [9]
Earlier this month, Citrix issued emergency updates for a NetScaler denial-of-service zero-day, CVE-2026-88779, that researchers and admins later said could also be exploited to gain remote code execution.
ReportedSupportedSource: BleepingComputer2 sources— create a free account to open themView cited source - [10]
CVE-2026-88771 and CVE-2026-88772 have been exploited in attacks against government, financial services, education, legal, and professional services organizations.
- [11]
Citrix issued the warning about CVE-2026-107406 on Thursday.
- [12]
The bug also affects Secure Private Access Hybrid deployments that use NetScaler, and customers need to update those NetScaler instances as well.
- [13]
Shadowserver tracks over 21,000 IP addresses with NetScaler fingerprints exposed on the internet.
- [14]
There is no information on how many of the Shadowserver-tracked NetScaler instances are honeypots, have already been patched, or have vulnerable configurations.
- [15]
Shadowserver's count includes just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances.
- [16]
CISA has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks.
- [17]
In March, Citrix urged customers to patch CVE-2026-3055 and CVE-2026-4368, which BleepingComputer cites among NetScaler vulnerabilities attackers have abused since the start of the year.
- [18]
ADC appliances make up more than nine in ten of the internet-exposed NetScaler fingerprints Shadowserver tracks.
Sources
2 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comCitrix warns admins to patch new NetScaler RCE flaw immediately
1 article · October 9, 2026
- securityweek.comCitrix Urges Immediate Patching of Critical NetScaler Vulnerability
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- SAML and federated identityFollow
- Patch And Redeploy LatencyFollow
- Network appliance vulnerabilitiesFollow