Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Citrix has urged customers to patch a critical security flaw in NetScaler ADC and NetScaler Gateway that could allow remote code execution or cause a denial of service. Tracked as CVE-2026-107406, the memory overflow vulnerability carries a CVSS v4.0 score of 9.5 and affects appliances with specific SAML settings. The security bulletin, CTX697191, was published on October 8, 2026.

Citrix said it was not aware of any unmitigated exploits when the bulletin was published. That statement should not be read as proof that every deployment is safe. Customers still need to check both their software build and authentication settings to determine whether the flaw applies.

The bulletin classifies the issue as CWE-119, meaning software does not properly restrict operations within a memory buffer. Successful exploitation could let an attacker run code or disrupt service. Its published severity vector describes a network attack requiring no privileges or user interaction, but with high attack complexity. Citrix has not provided detailed exploit instructions in the bulletin.

Citrix credited Michael Tucker, Chew Keong Tan, and Alex Bernier of the JPMorgan Chase XOR Team, along with Maxim Suhanov, for their work on the issue. The bulletin does not identify a specific attack campaign, victim organization, or public exploit, leaving those details outside the scope of the published advisory.

Which NetScaler Deployments Are Affected?

Exposure depends on whether NetScaler acts as a SAML identity provider, or IdP, or a service provider, or SP. These roles support single sign-on: the identity provider supplies authentication information, while the service provider uses it to grant access.

For NetScaler ADC and Gateway builds 14.1-73.37 through 14.1-73.41, and 13.1-64.23 through 13.1-64.28, the vulnerability applies only when the appliance is configured as a SAML IdP. Both ranges include their endpoints. The same condition covers NetScaler ADC 14.1-FIPS builds 14.1-73.37 through 14.1-73.41 FIPS, and 13.1-FIPS and NDcPP builds 13.1-37.279 through 13.1-37.282.

Deployments Affected (Source: Citrix)

Older supported builds have broader exposure. Versions before 14.1-73.37 or 13.1-64.23 are affected when configured as either a SAML SP or SAML IdP. The corresponding thresholds are 14.1-73.37 FIPS for 14.1-FIPS appliances and 13.1-37.279 for 13.1-FIPS and NDcPP deployments.

Administrators can check their configuration for add authentication samlAction, which identifies a SAML SP configuration, or add authentication samlIdPProfile, which identifies a SAML IdP configuration. Finding either entry is not enough by itself; teams must match the setting against the applicable version range.

Fixed Versions and Patching Priorities

Citrix recommends upgrading NetScaler ADC and Gateway to 14.1-73.46 or later on the 14.1 branch, or 13.1-64.29 or later on the 13.1 branch. NetScaler ADC 14.1-FIPS customers should install 14.1-73.46 FIPS or later. For 13.1-FIPS and NDcPP, the fixed build is 13.1-37.283 or later within those branches.

Secure Private Access Hybrid deployments using affected NetScaler instances also require updates. The bulletin covers customer-managed appliances, not Citrix-managed cloud services or Citrix-managed Adaptive Authentication, which the vendor updates.

The warning follows earlier NetScaler security updates. Cyber Security News recently covered a NetScaler SAML zero-day and appliance reboots following an earlier patch. Those reports provide useful background, but their recommended builds should not replace the fixes specified for this new vulnerability.

For administrators, the key distinction is that an appliance patched for an earlier issue may still need another upgrade. Teams should use CTX697191 as the reference for this flaw, confirm the SAML role on each affected appliance, and install the matching fixed release as soon as possible.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability appeared first on Cyber Security News.