Executive Summary
Citrix published a fix on 8 October for NetScaler CVE-2026-107406, a memory overflow in NetScaler ADC and NetScaler Gateway that ends in remote code execution or denial of service. It needs no credentials and no user interaction. The gate is the configuration. Only appliances running SAML as a service provider or an identity provider are in scope, and the builds that closed last week’s NetScaler flaw stay in scope when the box issues SAML assertions.
The finding is that a version number was never enough to judge exposure on this product. Citrix has taken three fixes on the same SAML path since 27 September. Two earlier flaws in the family are exploited in the wild and on the federal known exploited list. This one is not, and Citrix says it has seen no exploitation. Track the role, because the patch from last week does not cover every case.
Citrix pushed a critical NetScaler fix on 8 October. Days later, appliances that installed the fix from the week before are still exposed. The reason is a role, not a version.
NetScaler ADC and NetScaler Gateway sit at the network edge. They terminate remote access and single sign-on. When they broker SAML, they parse and issue XML assertions. CVE-2026-107406 is a memory overflow in that path, filed as CWE-119, and Citrix rates it 9.5 under CVSS 4.0. The vector is network, with high attack complexity, no privileges and no user interaction.

The fix from last week covers a different flaw
CVE-2026-88771 and CVE-2026-88772 went onto the federal known exploited list on 27 September, the same day Citrix published the fix. CVE-2026-88779 followed on 4 October and joined the list that day. CVE-2026-107406 arrived on 8 October in bulletin CTX697191.
Each fix closed one flaw and left the next one open. That is the pattern to internalize. An operator who patched on 4 October did the right thing and can still hold a vulnerable appliance today, if that appliance issues SAML assertions as an identity provider.
Your build number is not your exposure, your SAML role is
The affected bands are narrow and they split by role. On the 14.1 line, builds from 14.1-73.37 through 14.1-73.41 are affected only as a SAML identity provider. Anything before 14.1-73.37 is affected as a service provider or an identity provider. The 13.1 line runs the same split from 13.1-64.23 to 13.1-64.28. The fixed releases are 14.1-73.46 and 13.1-64.29.
There is a way to settle the role in one look. An appliance configured as a SAML service provider carries the line add authentication samlAction. One configured as an identity provider carries add authentication samlIdPProfile. Citrix credits Joshua Foote, Michael Tucker and Eugene Lim of the XOR Team at JPMorgan Chase with the find.
Patch is not remediation on an edge appliance
The earlier flaws in this family were exploited, and the post-exploitation kit is public. Security researchers describe webshells, a rogue superuser account, and a command-and-control framework built on the September zero days. A hotfix closes the door. It does not evict anyone who already walked through it.
That changes the order of operations. Upgrade first, then hunt for the artifacts. NVD published the record on 8 October and the bulletin lists no workaround, which leaves the upgrade as the only fix. Citrix also says Secure Private Access Hybrid deployments that use NetScaler instances need the same release.
Three questions worth answering this week. Does any NetScaler in your estate terminate SAML, and in which role. Which of them now sit on a build band that is open again. And if one of the earlier flaws was exploited, have you hunted for persistence, or did you only apply the upgrade.
Related reading. The same lesson showed up in the cache server that feeds vLLM, where an unauthenticated flaw handed out a root shell, and in the exposed GPU metrics endpoints where one bug could switch a fleet off.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
