Signal is active with 28 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC.
NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:
* For the following versions: Applicable only when configured as a SAML IdP:
* NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive
* NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
* NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive
* NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive
For the following versions: Applicable only when configured as a SAML SP or SAML IdP:
* NetScaler ADC and NetScaler Gateway before 14.1-73.37
* NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS
* NetScaler ADC and NetScaler Gateway before 13.1-64.23
* NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279
We have issued immediate guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway: https://bit.ly/4rWRBz4
We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
‼️ Citrix patches another critical NetScaler flaw as three separate bugs face active exploitation.
CVE-2026-107406 (CVSS 9.5) could enable RCE or DoS in affected SAML IdP/SP configurations. No evidence this flaw has been exploited.
Read > https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html
🚨 CITRIX PATCHES CRITICAL CVSS 9.5 NETSCALER SAML MEMORY-OVERFLOW FLAW (CVE-2026-107406)
Citrix published security bulletin CTX697191 for NetScaler ADC and NetScaler Gateway: a memory overflow that can lead to remote code execution or denial of service when the appliance is configured as a SAML SP or SAML IdP.
• CVE-2026-107406 — CWE-119 memory overflow; CVSS v4.0 base 9.5 (Critical)
• Precondition: SAML SP (`add authentication samlAction`) or SAML IdP (`add authentication samlIdPProfile`); version-specific IdP-only windows also apply
• Fixed builds: 14.1-73.46+, 13.1-64.29+, and matching 14.1-FIPS / 13.1-FIPS / NDcPP releases
• Also affects Secure Private Access Hybrid deployments that use customer-managed NetScaler instances
• Citrix-managed cloud services / Adaptive Authentication are upgraded by Citrix (no customer action)
⚠️ Analyst Note:
Citrix says it is not aware of any unmitigated exploits as of the Oct 8 bulletin. This is a new Critical patch on top of the recent NetScaler SAML/zero-day wave (CVE-2026-88771–88778 and CVE-2026-88779). Check SAML config and upgrade promptly. Not in the CISA KEV catalog as of Oct 8.
Official:
support[.]citrix[.]com/external/article/CTX697191
#DDW#DarkWeb#CyberSecurity#Citrix#NetScaler#CVE#PatchNow
#Murmeltier-Tag Kritische #Schwachstelle CVE-2026-107406 (CVSS 9.4) in #Citrix NetScaler ADC / Citrix NetScaler Gateway (8.10.2026) wenn diese Appliances als SAML-SP oder SAML-IdP konfiguriert sind. Also patchen.
https://borncity.com/blog/2026/10/09/kritische-schwachstelle-cve-2026-107406-in-citrix-netscaler-adc-citrix-netscaler-gateway-8-10-2026/
AUTHORIZATION REALITY • SAML AUTHENTICATION CONFIGURED DOES NOT PROVE THE IDENTITY GATEWAY RUNTIME IS SECURE
Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting specific versions and configurations of NetScaler ADC and NetScaler Gateway.
Under the documented conditions, the vulnerability can lead to remote code execution or denial of service in deployments using particular SAML Identity Provider or Service Provider configurations.
Citrix has released corrected versions and remediation guidance.
That is meaningful security maintenance.
But the broader assurance boundary deserves attention:
SAML AUTHENTICATION CONFIGURED ≠ IDENTITY GATEWAY RUNTIME SECURE
An enterprise gateway may correctly authenticate users.
It may validate identity assertions.
It may enforce application access policies.
Yet those controls do not prove that every underlying request-processing path remains within its intended execution boundary.
The stronger evidence chain is:
EXTERNAL REQUEST
→ SAML PROCESSING
→ IDENTITY GATEWAY
→ RUNTIME PROCESSING
→ EXECUTION AUTHORITY
→ OBSERVED EFFECT
→ VERIFIED EFFECT
This distinction matters because identity infrastructure is often treated as a trust anchor.
But authentication correctness and runtime security are different properties.
A valid SAML flow does not prove that the gateway processing it is free from exploitable runtime defects.
Likewise:
PATCH AVAILABLE ≠ PATCH DEPLOYED
PATCH DEPLOYED ≠ EFFECT VERIFIED
NO KNOWN EXPLOIT ≠ NO EXPLOIT EXISTS
And product name alone is not enough to establish exposure.
VERSION MATTERS.
CONFIGURATION MATTERS.
RUNTIME STATE MATTERS.
The advisory does not establish that every NetScaler deployment is affected.
Nor does it prove that any particular organization was compromised.
The next assurance step is to verify the actual deployed version, effective SAML role, exposure conditions, remediation state and resulting runtime behavior.
That is the distinction EVELIQ Trace is focused on making reconstructable:
what was configured,
what was exposed,
what changed,
what actually ran,
and what effect can be verified.
EVELIQ Trace • Evidence Intelligence Platform.
We don’t score people. We verify project reality.
Founder: Roland Brüggemann
AI-assisted research, structure, architecture & concept development: OpenAI ChatGPT
Source context: Citrix Security Bulletin CTX697191 / CVE-2026-107406
#Authorization#IdentitySecurity#SAML#CyberSecurity#RuntimeSecurity#EvidenceIntelligence#EVELIQTrace
ثغرة حرجة من نوع تجاوز سعة الذاكرة (CVE-2026-107406 بتقييم CVSS عند 9.5) في أنظمة NetScaler ADC وNetScaler Gateway، تتيح تنفيذ تعليمات عن بعد أو إيقاف الخدمة.
تؤثر على الأجهزة المهيأة كمزود خدمة أو مزود هوية عبر SAML.
يمكن استغلالها عن بعد دون صلاحيات أو تفاعل من المستخدم. https://t.co/puEGGOLNv9
Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix#NetScaler#NetScalerGateway#CVE2026107406#SAML#RCE#PatchNow#Vulnerability
https://securityonline.info/citrix-netscaler-vulnerability-cve-2026-107406/
🚨 Upozorňujeme na kritickou zranitelnost v Citrix NetScaler ADC a NetScaler Gateway, CVE-2026-107406.
Zranitelnost typu přetečení paměťového zásobníku s hodnocením CVSS 9.5 umožňuje vzdálenému útočníkovi spuštění libovolného kódu nebo vyvolání odepření služby (DoS), čímž může dojít k narušení důvěrnosti, integrity a dostupnosti zařízení. Zneužití závisí na použité verzi softwaru a konfiguraci zařízení jako poskytovatele služby SAML (SP) nebo poskytovatele identity SAML (IdP), zejména na přítomnosti konfiguračních položek „add authentication samlAction“ nebo „add authentication samlIdPProfile“.
Zranitelné jsou NetScaler ADC a NetScaler Gateway 14.1 před verzí 14.1-73.46, řada 13.1 před verzí 13.1-64.29, NetScaler ADC 14.1-FIPS před verzí 14.1-73.46 FIPS a NetScaler ADC 13.1-FIPS / 13.1-NDcPP před verzí 13.1-37.283.
🚨 عاجل: Citrix تنبّه عملاء NetScaler ADC و NetScaler Gateway يسدّون ثغرة خطيرة بسرعة
الثغرة تسمح بتنفيذ كود عن بعد (RCE) أو تعطّل الخدمة (denial of service)، ومسجّلة باسم CVE-2026-107406، وتقييمها CVSS v4.0 هو 9.5، يعني من أشد الثغرات، وتضرب الأجهزة اللي فيها إعدادات SAML معينة.
البلتن الأمني CTX697191 نزل بتاريخ 8 أكتوبر 2026، وقالت Citrix إنها ما كانت تدري عن أي استغلال فعلي وقتها.. بس لا تفهمون هالكلام إن كل نشر آمن.
NetScaler ADC & Gateway appliances are exposed: a critical remote code execution vulnerability (CVE-2026-107406) has surfaced, impacting builds under certain SAML SP/IdP settings. CVSS v4.0 at 9.5—no user interaction required. Critical to verify your appliance role (SP vs IdP), check versions (14.1-73.37-73.41, 13.1-64.23-64.28 and older), and upgrade to fixed builds like 14.1-73.46 or 13.1-64.29 ASAP. #Security#Citrix#RCE#NetScalerADC#Patching#Vulnerability#Citrix#NetScaler#RCE#Vulnerability#Cybersecurity#Patching
https://thedailytechfeed.com/new-critical-rce-found-in-citrix-netscaler-adc-gateway-patch-now/
CRITICAL SECURITY ALERT | CITRIX NETSCALER
CVE-2026-107406 (CVSS 9.5) may lead to Remote Code Execution or Denial of Service on affected systems configured as SAML SP or IdP.
Install the appropriate updated versions as soon as possible.
Help: servicedesk@intrasystems.com
Citrix disclosed CVE-2026-107406, a memory overflow affecting NetScaler ADC and Gateway appliances configured as SAML IdPs or SPs. It can enable remote code execution or denial of service; Citrix says it has no evidence of exploitation and urges upgrades.
https://cyber.hendryadrian.com/article/732/citrix-urges-admins-to-patch-critical-netscaler-rce-and-dos-flaw
🚨 Citrix NetScaler Alert
Citrix urges immediate patching of critical NetScaler flaw (CVE-2026-107406). Could allow RCE or DoS in SAML setups. Patch now!
#CyberSecurity#NetScaler#PatchNow#InfoSec
🚨 NetScaler CVE-2026-107406: critical SAML flaw (CVSS 9.5) that can lead to RCE, no login needed
⚠️ Patched last week for CVE-2026-88779? SAML IdP setups are STILL exposed
🛡️ No workaround: upgrade to 14.1-73.46 or 13.1-64.29
📆 3rd NetScaler bulletin in 12 days
Read full article - https://badgersignal.com/articles/critical-netscaler-adcgateway-memory-overflow-cve2026107406-requires-immediate-patch
#Citrix#NetScaler#PatchNow