Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Citrix urges administrators to promptly upgrade affected NetScaler systems after disclosing CVE-2026-107406, a critical memory-overflow vulnerability that can cause remote code execution (RCE) or denial of service (DoS). Exposure depends on the appliance’s exact release track and build, and whether it is configured as a SAML service provider (SP) or identity provider (IdP). Check both before determining whether your deployment is affected.

What Citrix disclosed

In a security bulletin initially published October 8, 2026, Citrix described CVE-2026-107406 as a “Memory overflow vulnerability leading to Remote Code Execution or Denial of Service.” Cloud Software Group rates it Critical and gives it a 9.5 (CVSS v4.0 base score) — Cloud Software Group, 2026. That is the bulletin’s severity rating, not a measure of incidents or the likelihood that a particular appliance will be compromised.

The bulletin does not confirm active exploitation or report affected-customer counts. Its warning is about conditional exposure: the release track, installed build, and SAML configuration all matter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which NetScaler deployments may be affected

Citrix’s notice covers customer-managed NetScaler ADC and NetScaler Gateway, including NetScaler instances in Secure Private Access Hybrid deployments. Citrix says Cloud Software Group will update Citrix-managed cloud services and Citrix-managed Adaptive Authentication. For customer-managed appliances, use the version-specific conditions below rather than treating all NetScaler installations as affected.

Product track and build SAML configuration required by the bulletin
Standard ADC/Gateway 14.1-73.37 through 14.1-73.41, inclusive SAML IdP
Standard ADC/Gateway 13.1-64.23 through 13.1-64.28, inclusive SAML IdP
Standard ADC/Gateway builds before 14.1-73.37 SAML SP or SAML IdP
Standard ADC/Gateway builds before 13.1-64.23 SAML SP or SAML IdP
ADC 14.1-FIPS 14.1-73.37 FIPS through 14.1-73.41 FIPS SAML IdP
ADC 14.1-FIPS versions before 14.1-73.37 FIPS SAML SP or SAML IdP
ADC 13.1-FIPS/NDcPP: 13.1-NDcPP 13.1-37.279 through 13.1-37.282 SAML IdP
ADC 13.1-FIPS/NDcPP versions before 13.1-NDcPP 13.1-37.279 SAML SP or SAML IdP

These conditions preserve Citrix’s distinctions between standard, FIPS, and NDcPP builds. If your installed version or track does not fit these entries clearly, consult the version table in Citrix’s CVE-2026-107406 security bulletin rather than inferring applicability from a nearby build number.

How to check your SAML configuration and build

  1. Identify the exact product track and installed build. Determine whether the appliance is standard ADC/Gateway, 14.1-FIPS, or 13.1-FIPS/NDcPP, and record the full version string.
  2. Search the appliance configuration for the SAML entries. Citrix identifies add authentication samlAction for a SAML SP and add authentication samlIdPProfile for a SAML IdP. Use your normal configuration review process to find whether either entry is present.
  3. Match both findings to the table. For the middle build ranges listed above, the bulletin specifies IdP configuration; for the earlier ranges, it specifies SP or IdP configuration. Apply the condition for your exact track and build.
  4. Use the matching fixed release floor if affected. Upgrade to Citrix’s recommended fixed version or a later release in the same product track.

Finding a SAML string alone does not establish exposure. The version and configuration conditions must be considered together.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Fixed releases Citrix recommends

Citrix strongly urges affected customers to install the listed updates as soon as possible. The fixed release floors differ by product track:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product track Fixed release floor
NetScaler ADC and NetScaler Gateway 14.1 14.1-73.46 and later
NetScaler ADC and NetScaler Gateway 13.1 13.1-64.29 and later 13.1 releases
NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later 14.1-FIPS releases
NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases in those tracks

Choose the release that matches the appliance’s track; a standard-build number is not interchangeable with its FIPS or NDcPP counterpart. Citrix’s bulletin does not provide a non-upgrade workaround.

Where to get help

Citrix directs customers who need technical assistance to Citrix Technical Support and recommends subscribing to alerts for new or updated security bulletins. The bulletin acknowledges Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov, for working with Citrix to protect customers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.