CVE-2026-107406

LOWCVSS 9.5 · CRITICAL

Signal is active with 28 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 35 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 28 mentions on most recent observed day (2026-10-09)
  • 35 total mentions across 2 days

Deep dive

Activity timeline35 mentions / 2d
07142128Mentions · 2026-10-08: 7Mentions · 2026-10-09: 2810-0810-09
Referenced assets27 URLs
By indicator
Full discourse20 posts
  • Citrix@citrix

    We have issued immediate guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway: https://bit.ly/4rWRBz4 We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.

    102717804424.5K
    197.1K followersView on X
  • Thomas Poppelgaard@_POPPELGAARD

    🚨 New critical NetScaler CVE: CVE-2026-107406 (CTX697191, CVSS 9.5) – SAML → RCE. No workaround. 📄 https://support.citrix.com/external/article/CTX697191 SAML IdP on 73.41 / 64.28? Upgrade again to 73.46 / 64.29. 🛠️ Checker v1.16: https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker #NetScaler #Citrix #CVE2026107406 https://t.co/YwrLkTxr0C

    310132173.6K
    4.3K followersView on X
  • The Hacker News@TheHackersNews

    ‼️ Citrix patches another critical NetScaler flaw as three separate bugs face active exploitation. CVE-2026-107406 (CVSS 9.5) could enable RCE or DoS in affected SAML IdP/SP configurations. No evidence this flaw has been exploited. Read > https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html

    2802749.5K
    2.4M followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CITRIX PATCHES CRITICAL CVSS 9.5 NETSCALER SAML MEMORY-OVERFLOW FLAW (CVE-2026-107406) Citrix published security bulletin CTX697191 for NetScaler ADC and NetScaler Gateway: a memory overflow that can lead to remote code execution or denial of service when the appliance is configured as a SAML SP or SAML IdP. • CVE-2026-107406 — CWE-119 memory overflow; CVSS v4.0 base 9.5 (Critical) • Precondition: SAML SP (`add authentication samlAction`) or SAML IdP (`add authentication samlIdPProfile`); version-specific IdP-only windows also apply • Fixed builds: 14.1-73.46+, 13.1-64.29+, and matching 14.1-FIPS / 13.1-FIPS / NDcPP releases • Also affects Secure Private Access Hybrid deployments that use customer-managed NetScaler instances • Citrix-managed cloud services / Adaptive Authentication are upgraded by Citrix (no customer action) ⚠️ Analyst Note: Citrix says it is not aware of any unmitigated exploits as of the Oct 8 bulletin. This is a new Critical patch on top of the recent NetScaler SAML/zero-day wave (CVE-2026-88771–88778 and CVE-2026-88779). Check SAML config and upgrade promptly. Not in the CISA KEV catalog as of Oct 8. Official: support[.]citrix[.]com/external/article/CTX697191 #DDW #DarkWeb #CyberSecurity #Citrix #NetScaler #CVE #PatchNow

    1001223.6K
    207.7K followersView on X
  • Securityblog@Securityblog

    Citrix Netscaler CVE advisory: CVE-2026-107406 https://support.citrix.com/support-home/k… Third week in a row…seriously @citrix ??

    10060576
    12.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi

    هالفتره برعاية Citrix 🤦🏻‍♂️ ثغرة جديده في NetScaler اذا جهتك تستخدم NetScaler حدث في اقرب وقت CVE-2026-107406 https://bit.ly/4rWRBz4

    10022863
    50.2K followersView on X
  • VulniPulse@vulnipulse

    CVE advisory: CVE-2026-107406 - netscaler: Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway. https://vulnipulse.com/advisories/netscaler-protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and #CVE #CyberSecurity #NetScaler #NetScalerADC

    03011294
    12 followersView on X
  • Günter Born@etguenni

    #Murmeltier-Tag Kritische #Schwachstelle CVE-2026-107406 (CVSS 9.4) in #Citrix NetScaler ADC / Citrix NetScaler Gateway (8.10.2026) wenn diese Appliances als SAML-SP oder SAML-IdP konfiguriert sind. Also patchen. https://borncity.com/blog/2026/10/09/kritische-schwachstelle-cve-2026-107406-in-citrix-netscaler-adc-citrix-netscaler-gateway-8-10-2026/

    01020315
    2.9K followersView on X
  • Fredrik L. Andersen@ifredriks

    @watchtowrcyber CVE-2026-107406⁠ https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191&articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_107406

    01020444
    1.2K followersView on X
  • Roland Brüggemann | EVELIQ Trace@eveliqTrace

    AUTHORIZATION REALITY • SAML AUTHENTICATION CONFIGURED DOES NOT PROVE THE IDENTITY GATEWAY RUNTIME IS SECURE Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting specific versions and configurations of NetScaler ADC and NetScaler Gateway. Under the documented conditions, the vulnerability can lead to remote code execution or denial of service in deployments using particular SAML Identity Provider or Service Provider configurations. Citrix has released corrected versions and remediation guidance. That is meaningful security maintenance. But the broader assurance boundary deserves attention: SAML AUTHENTICATION CONFIGURED ≠ IDENTITY GATEWAY RUNTIME SECURE An enterprise gateway may correctly authenticate users. It may validate identity assertions. It may enforce application access policies. Yet those controls do not prove that every underlying request-processing path remains within its intended execution boundary. The stronger evidence chain is: EXTERNAL REQUEST → SAML PROCESSING → IDENTITY GATEWAY → RUNTIME PROCESSING → EXECUTION AUTHORITY → OBSERVED EFFECT → VERIFIED EFFECT This distinction matters because identity infrastructure is often treated as a trust anchor. But authentication correctness and runtime security are different properties. A valid SAML flow does not prove that the gateway processing it is free from exploitable runtime defects. Likewise: PATCH AVAILABLE ≠ PATCH DEPLOYED PATCH DEPLOYED ≠ EFFECT VERIFIED NO KNOWN EXPLOIT ≠ NO EXPLOIT EXISTS And product name alone is not enough to establish exposure. VERSION MATTERS. CONFIGURATION MATTERS. RUNTIME STATE MATTERS. The advisory does not establish that every NetScaler deployment is affected. Nor does it prove that any particular organization was compromised. The next assurance step is to verify the actual deployed version, effective SAML role, exposure conditions, remediation state and resulting runtime behavior. That is the distinction EVELIQ Trace is focused on making reconstructable: what was configured, what was exposed, what changed, what actually ran, and what effect can be verified. EVELIQ Trace • Evidence Intelligence Platform. We don’t score people. We verify project reality. Founder: Roland Brüggemann AI-assisted research, structure, architecture & concept development: OpenAI ChatGPT Source context: Citrix Security Bulletin CTX697191 / CVE-2026-107406 #Authorization #IdentitySecurity #SAML #CyberSecurity #RuntimeSecurity #EvidenceIntelligence #EVELIQTrace

    1001044
    62 followersView on X
  • سايبركاست@cyberscastx

    ثغرة حرجة من نوع تجاوز سعة الذاكرة (CVE-2026-107406 بتقييم CVSS عند 9.5) في أنظمة NetScaler ADC وNetScaler Gateway، تتيح تنفيذ تعليمات عن بعد أو إيقاف الخدمة. تؤثر على الأجهزة المهيأة كمزود خدمة أو مزود هوية عبر SAML. يمكن استغلالها عن بعد دون صلاحيات أو تفاعل من المستخدم. https://t.co/puEGGOLNv9

    00011345
    7.0K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now. #Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability https://securityonline.info/citrix-netscaler-vulnerability-cve-2026-107406/

    01010395
    13.0K followersView on X
  • GovCERT.CZ@GOVCERT_CZ

    🚨 Upozorňujeme na kritickou zranitelnost v Citrix NetScaler ADC a NetScaler Gateway, CVE-2026-107406. Zranitelnost typu přetečení paměťového zásobníku s hodnocením CVSS 9.5 umožňuje vzdálenému útočníkovi spuštění libovolného kódu nebo vyvolání odepření služby (DoS), čímž může dojít k narušení důvěrnosti, integrity a dostupnosti zařízení. Zneužití závisí na použité verzi softwaru a konfiguraci zařízení jako poskytovatele služby SAML (SP) nebo poskytovatele identity SAML (IdP), zejména na přítomnosti konfiguračních položek „add authentication samlAction“ nebo „add authentication samlIdPProfile“. Zranitelné jsou NetScaler ADC a NetScaler Gateway 14.1 před verzí 14.1-73.46, řada 13.1 před verzí 13.1-64.29, NetScaler ADC 14.1-FIPS před verzí 14.1-73.46 FIPS a NetScaler ADC 13.1-FIPS / 13.1-NDcPP před verzí 13.1-37.283.

    00010210
    4.3K followersView on X
  • Manuel Winkel@Deyda84

    Citrix’s latest NetScaler bulletin covers CVE-2026-107406 (Critical, CVSS 9.5): a SAML-related memory overflow with potential RCE or DoS. Check your build and SAML role. Fixed: 14.1-73.46+, 13.1-64.29+. Checklist: https://www.deyda.net/index.php/de/2026/08/28/netscaler-cve-checkliste-updates-sicherheitspruefung-und-incident-response/ Bulletin: https://support.citrix.com/external/article/CTX697191

    00010113
    1.4K followersView on X
  • ابو سعود 💻@AbuSaud_Cyber

    🚨 عاجل: Citrix تنبّه عملاء NetScaler ADC و NetScaler Gateway يسدّون ثغرة خطيرة بسرعة الثغرة تسمح بتنفيذ كود عن بعد (RCE) أو تعطّل الخدمة (denial of service)، ومسجّلة باسم CVE-2026-107406، وتقييمها CVSS v4.0 هو 9.5، يعني من أشد الثغرات، وتضرب الأجهزة اللي فيها إعدادات SAML معينة. البلتن الأمني CTX697191 نزل بتاريخ 8 أكتوبر 2026، وقالت Citrix إنها ما كانت تدري عن أي استغلال فعلي وقتها.. بس لا تفهمون هالكلام إن كل نشر آمن.

    00001376
    1.8K followersView on X
  • The Daily Tech Feed@dailytechonx

    NetScaler ADC & Gateway appliances are exposed: a critical remote code execution vulnerability (CVE-2026-107406) has surfaced, impacting builds under certain SAML SP/IdP settings. CVSS v4.0 at 9.5—no user interaction required. Critical to verify your appliance role (SP vs IdP), check versions (14.1-73.37-73.41, 13.1-64.23-64.28 and older), and upgrade to fixed builds like 14.1-73.46 or 13.1-64.29 ASAP. #Security #Citrix #RCE #NetScalerADC #Patching #Vulnerability #Citrix #NetScaler #RCE #Vulnerability #Cybersecurity #Patching https://thedailytechfeed.com/new-critical-rce-found-in-citrix-netscaler-adc-gateway-patch-now/

    00010104
    787 followersView on X
  • IntraSystems, LLC@Intra_Access

    CRITICAL SECURITY ALERT | CITRIX NETSCALER CVE-2026-107406 (CVSS 9.5) may lead to Remote Code Execution or Denial of Service on affected systems configured as SAML SP or IdP. Install the appropriate updated versions as soon as possible. Help: servicedesk@intrasystems.com

    00010222
    308 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    Citrix disclosed CVE-2026-107406, a memory overflow affecting NetScaler ADC and Gateway appliances configured as SAML IdPs or SPs. It can enable remote code execution or denial of service; Citrix says it has no evidence of exploitation and urges upgrades. https://cyber.hendryadrian.com/article/732/citrix-urges-admins-to-patch-critical-netscaler-rce-and-dos-flaw

    0000068
    4.9K followersView on X
  • ChrisUK2026@chris_uk2026

    🚨 Citrix NetScaler Alert Citrix urges immediate patching of critical NetScaler flaw (CVE-2026-107406). Could allow RCE or DoS in SAML setups. Patch now! #CyberSecurity #NetScaler #PatchNow #InfoSec

    0000013
    33 followersView on X
  • Badger Signal@BadgerSignalHQ

    🚨 NetScaler CVE-2026-107406: critical SAML flaw (CVSS 9.5) that can lead to RCE, no login needed ⚠️ Patched last week for CVE-2026-88779? SAML IdP setups are STILL exposed 🛡️ No workaround: upgrade to 14.1-73.46 or 13.1-64.29 📆 3rd NetScaler bulletin in 12 days Read full article - https://badgersignal.com/articles/critical-netscaler-adcgateway-memory-overflow-cve2026107406-requires-immediate-patch #Citrix #NetScaler #PatchNow

    0000014
    8 followersView on X

Explore more