Citrix has issued an urgent fix for a remote code execution (RCE) flaw in NetScaler ADC and NetScaler Gateway appliances, warning that the issue could also lead to denial of service. Tracked as **CVE-2026-107406**, the vulnerability stems from a memory buffer overflow under certain SAML authentication settings. With a high severity rating—CVSS v4.0 score of **9.5**—this flaw is detailed in security bulletin **CTX697191**, published October 8, 2026.
How and Where the Risk Arises
The bug is classified under **CWE-119**, meaning it involves improper handling of memory buffers. If exploited, it can allow an attacker to execute arbitrary code or disrupt the service. Disturbingly, the attack requires no user privileges or interaction, though the attack complexity is rated high. As of the bulletin’s release, Citrix has not identified any active exploits or campaigns using this vulnerability, but stresses that no deployment should be assumed safe without verification.
Which Versions Are Affected & Configuration Matters
The flaw impacts several builds of NetScaler ADC and Gateway, depending on whether the appliance is configured as a SAML **Identity Provider (IdP)** or **Service Provider (SP)**. Appliances running builds 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, are vulnerable—but only when set up as an IdP. The same holds for 14.1-FIPS builds 14.1-73.37-73.41 and 13.1-FIPS/NDcPP builds 13.1-37.279-37.282. Older builds before these thresholds risk exposure in both IdP or SP roles.
Administrators should inspect their setups—particularly looking for configurations involving “add authentication samlAction” (SP) or “add authentication samlIdPProfile” (IdP)—and cross-reference these against the build versions in their environment to judge exposure.
Patches and Mitigations
Fixed releases are already available: upgrade to **14.1-73.46 or newer** on the 14.1 branch, or **13.1-64.29 or newer** on the 13.1 branch. For FIPS versions, the minimum safe builds are **14.1-73.46 FIPS**, and **13.1-37.283 or above** for 13.1-FIPS/NDcPP deployments. If a NetScaler appliance is used as part of a Secure Private Access Hybrid deployment, those should be updated too. Citrix-managed cloud services and Adaptive Authentication platforms are outside this advisory—they’re updated by Citrix directly.
This vulnerability follows recent troubles with NetScaler, including a previous SAML zero-day and issues causing unwanted reboots after past patches. Those past fixes do not cover this new problem; each installation must apply the new bulletin’s versions independently.
What To Do Now: Use **CTX697191** as the reference when checking your NetScaler instances. Verify both the **build version and the SAML role** (IdP vs SP). If any device falls within the affected version ranges, install the appropriate patched release immediately.
Your patching schedule or prior updates do **not** guarantee protection against this issue unless they match these specific fixes.
As organizations increasingly depend on remote access and single sign-on mechanisms, vulnerabilities in authentication layers like SAML pose very serious risks. The high severity and zero interaction requirement of this flaw make timely patching essential. Keep an eye on upcoming advisories in case proof-of-concept exploits emerge, and inventory your authentication roles across all NetScaler deployments without delay to ensure no unprotected systems remain.