Citrix has released fixes for CVE-2026-107406, a critical vulnerability in NetScaler ADC and NetScaler Gateway that can allow remote code execution or denial of service. The company issued the patches on October 9 as part of a release covering eight security flaws, as first reported by The Register.
The bug carries a CVSS v4.0 score of 9.5. Citrix traced it to improper restrictions on memory-buffer operations, a weakness categorized as CWE-119. The company credited Michael Tucker, Chew Keong Tan and Alex Bernier of JPMorgan Chase’s XOR Team, along with security researcher Maxim Suhanov, for finding it.
SAML configuration determines exposure
Older affected releases are exposed when administrators configure the appliances as either SAML service providers or SAML identity providers. Some newer affected releases face the risk only when set up as SAML identity providers. Secure Private Access Hybrid deployments that use these instances also need the fixes.
SAML handles authentication exchanges between services, identity platforms and users. A fault in that path can put systems that sit at the edge of an organization’s network within reach of an unauthenticated attacker, depending on the vulnerable deployment’s configuration.
NetScaler’s recent security record raises the stakes
Citrix customers running self-managed installations must apply the updates themselves. Citrix said it is applying the required remediation to its managed cloud services and Adaptive Authentication offerings.
The release follows another serious SAML-related NetScaler issue, CVE-2026-88779, which received a severity score of 8.7 and involved memory overflows. Google researchers also reported exploitation of CVE-2026-88772 from at least early September 2026. That campaign reportedly put organizations in North American and European government, finance, legal and education sectors at risk, making prompt patching important for administrators with internet-facing authentication infrastructure.
Citrix has not said whether CVE-2026-107406 was exploited before disclosure or whether attackers have used it in the wild. The available release summaries also do not identify the affected software builds or the precise versions containing the corrections, so administrators will need to consult Citrix’s product advisories to map their deployments to the appropriate update.
This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.