NetScaler CVE-2026-107406: last week's SAML patch isn't enough
Citrix NetScaler CVE-2026-107406 (CVSS 9.5) hits SAML IdP builds up to 14.1-73.41, the fix for last week's KEV bug. Patch to 14.1-73.46 or 13.1-64.29.
If you patched your Citrix NetScaler last week for the SAML flaw on CISA's exploited list, you're not done. Citrix published CVE-2026-107406 on October 8: a new SAML memory overflow rated CVSS v4.0 9.5, with remote code execution on the table. The build that fixed last week's bug, 14.1-73.41, is still vulnerable when the box runs as a SAML identity provider. Patch again.
What actually happened
Citrix bulletin CTX697191 describes CVE-2026-107406 as a memory overflow "leading to Remote Code Execution or Denial of Service" (CWE-119). The precondition: NetScaler ADC or Gateway configured as a SAML Service Provider or SAML Identity Provider.
The affected ranges split two ways:
- SP or IdP: builds before 14.1-73.37 and before 13.1-64.23 (plus matching FIPS and NDcPP lines)
- IdP only: 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28
Those IdP-only ranges are the builds most teams installed for CVE-2026-88779, which CISA gave federal agencies three days to fix. The fixed builds now are:
- 14.1-73.46 and later
- 13.1-64.29 and later
- 14.1-73.46 FIPS and later
- 13.1-37.283 and later (FIPS and NDcPP)
Secure Private Access hybrid deployments that use NetScaler instances need the update too. Citrix patches its own managed cloud services and Adaptive Authentication. Self-hosted boxes are your job.
Citrix doesn't say whether this one is exploited. The Register found no word on that either. We don't treat that as comfort. The previous SAML bug was labeled denial of service and went onto the exploited list anyway.
Why it matters for your business
A NetScaler running SAML is your login broker. It decides who gets into your VPN, Microsoft 365, and internal apps. This is the third emergency patch on these appliances in about two weeks. At that pace, a quarterly patch window means you're exposed most of the time.
What we'd do today:
- Run
show version. If you see 14.1-73.41 or 13.1-64.28, last week's fix, you still need this one. - Grep the config for
samlIdPProfileandsamlAction. IdP profiles are what keep the newer builds exposed. - Patch to 14.1-73.46 or 13.1-64.29. Then check that the version actually changed.
- If you've been exposed since September, investigate. Look for unknown processes and files, and rotate SAML signing certificates and service account credentials.
Key takeaways
- CVE-2026-107406 is a CVSS 9.5 SAML memory overflow in NetScaler ADC and Gateway, published October 8
- Builds 14.1-73.41 and 13.1-64.28, last week's fix for CVE-2026-88779, are still vulnerable as a SAML IdP
- Fixed in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1-37.283 and later
- Citrix hasn't said whether it's exploited; the last SAML bug was exploited despite a DoS label
- Secure Private Access hybrid setups on NetScaler need the patch too
Three NetScaler fire drills in two weeks is a process problem. We give every internet-facing box a named owner, a version check against each new bulletin, and a patch window measured in hours. See what we operate, or tell us what sits in front of your SSO.
Sources: Citrix CTX697191, The Register.
- #citrix
- #netscaler
- #cve
- #saml
- #patching
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
OutSystems Agent Experience GA: coding agents with guardrails
OutSystems Agent Experience is GA, opening its low-code platform to Claude Code, Cursor, Codex and Kiro. Speed was never the problem. Rework was.
Read itGitHub's AI secret detection model bills credits on every push
GitHub's new AI secret detection model finds passwords with no token format. AI push protection now uses AI Credits. Set a hard budget cap before you opt in.
Read it