Skip to content
TrustList
News

Citrix fixes CVSS 9.5 NetScaler SAML flaw; no attacks seen so far

Editorial

By TrustList Editorial

Only appliances configured as a SAML service provider or identity provider are exposed; Citrix knows of no exploitation yet, and Shadowserver counts about 21,000 NetScaler fingerprints online.

About Citrix fixes CVSS 9.5 NetScaler SAML flaw; no attacks seen so far

Citrix fixes CVSS 9.5 NetScaler SAML flaw; no attacks seen so far

8 October 2026: Citrix has fixed CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or a crash. It scores 9.5 on CVSS v4.0, needs no login, and applies only to appliances set up for SAML single sign-on. Citrix published bulletin CTX697191 on 8 October.

The bug sits in the SAML code, so the exposure depends on configuration. Appliances acting as a SAML service provider (SP) or identity provider (IdP) are in scope on older builds; on some newer builds only the IdP role is affected. Admins can check by looking in the running configuration for add authentication samlAction (service provider) or add authentication samlIdPProfile (identity provider). Deployments of Secure Private Access Hybrid that use NetScaler instances need the same upgrade. Citrix-managed cloud services and Adaptive Authentication are updated by Cloud Software Group itself.

Affected and fixed builds

Builds in the IdP-only band are 14.1-73.37 to 14.1-73.41, 13.1-64.23 to 13.1-64.28, and 13.1-NDcPP 13.1-37.279 to 13.1-37.282. Anything older than those bands is affected whichever SAML role it plays. The fixed releases are:

  • 14.1-73.46 and later
  • 13.1-64.29 and later 13.1 releases
  • 14.1-FIPS 14.1-73.46 FIPS and later
  • 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later

The bulletin lists no workaround, so upgrading is the only remedy. Citrix credits Joshua Foote, Michael Tucker and Eugene Lim of the XOR Team at JPMorgan Chase for the report.

Exploitation and context

Citrix says it is not aware of any unmitigated exploits, and BleepingComputer reports no sign of attacks in the wild. That separates this flaw from CVE-2026-88771 and CVE-2026-88772, which were exploited as zero-days in September, and from the CVE-2026-88779 denial-of-service zero-day patched earlier in October. Builds that carry the earlier fixes are still inside the affected bands above, so those upgrades do not cover this one.

Shadowserver counts about 21,000 exposed NetScaler fingerprints, roughly 1,500 Gateway and 20,000 ADC, though it is unclear how many are honeypots or already patched. CISA has listed 27 actively exploited Citrix vulnerabilities since November 2021.

Company profile on TrustList: Citrix

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy