Threat reportVulnerabilityTL-2026-3078
Citrix NetScaler ADC and Gateway Critical Memory Overflow RCE in SAML SP/IdP Configurations (CVE-2026-107406)
Citrix NetScaler ADC and Gateway Critical Memory Overflow (TL-2026-3078), also tracked as CTX697191, is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-10-09. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway 14.1, references 1 CVE (CVE-2026-107406), maps to 5 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 9.5/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-3078
- Threat ID
- TL-2026-3078
- Also known as
- CTX697191
- Severity
- CRITICAL
- CVSS
- 9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, telecoms, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
- Updates
- 2026-10-09 · revalidated 1× · latest source
How Citrix NetScaler ADC and Gateway Critical Memory Overflow works
Citrix disclosed CVE-2026-107406 (CVSS v4.0 9.5), a memory overflow in NetScaler ADC and NetScaler Gateway that may lead to remote code execution or denial of service when the appliance is configured as a SAML Service Provider or Identity Provider. Citrix is not aware of unmitigated exploits at publication; patched builds are available.
CVE-2026-107406 is a memory overflow (classified in reporting as CWE-119, improper restriction of operations within the bounds of a memory buffer) in NetScaler ADC and NetScaler Gateway, published 2026-10-08 in Citrix security bulletin CTX697191. Successful exploitation may lead to remote code execution or denial of service. NVD records the CVSS v4.0 vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L (base score 9.5): network-reachable, no privileges or user interaction required, high attack complexity.
Exposure depends on SAML configuration. On builds before 14.1-73.37 and 13.1-64.23, the appliance is vulnerable when configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). On the newer builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 (and the corresponding FIPS/NDcPP builds), the flaw applies only when the appliance is configured as a SAML IdP. Appliances without SAML configuration are not affected. Defenders can identify exposure by looking for 'add authentication samlAction' (SAML SP role) and 'add authentication samlIdPProfile' (SAML IdP role) in the running configuration. Secure Private Access hybrid deployments using NetScaler are affected; Citrix-managed cloud services and Adaptive Authentication are reported as unaffected.
At publication Citrix stated it was not aware of any unmitigated exploits; no public proof-of-concept, no named threat actors and no indicators of compromise have been reported. The finding was credited to Michael Tucker, Chew Keong Tan, Alex Bernier (JPMorgan Chase XOR Team) and Maxim Suhanov. Context for prioritization: NetScaler has been repeatedly exploited in 2026, and a closely related SAML memory overflow, CVE-2026-88779 (CVSS 8.7, DoS, reported by Bishop Fox and watchTowr), was added to CISA KEV on 2026-10-04 after targeted exploitation. CVE-2026-107406 is a separate CVE and was not listed in the KEV content reviewed. The ATT&CK mappings below are anticipated attacker behaviors for an internet-facing appliance memory-corruption flaw, not observed activity.
MITRE ATT&CK techniques used in TL-2026-3078
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Resource Development
T1587.004 Develop Capabilities: Exploits
Reconnaissance
Affected products and versions in Citrix NetScaler ADC and Gateway Critical Memory Overflow
- Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway 14.1
Vulnerable versions: 14.1-73.37 through 14.1-73.41 (SAML IdP only); builds before 14.1-73.37 (SAML SP or IdP)
Fixed in: 14.1-73.46 and later - Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway 13.1
Vulnerable versions: 13.1-64.23 through 13.1-64.28 (SAML IdP only); builds before 13.1-64.23 (SAML SP or IdP)
Fixed in: 13.1-64.29 and later - Citrix (Cloud Software Group) — NetScaler ADC 14.1-FIPS
Vulnerable versions: 14.1-73.37 through 14.1-73.41
Fixed in: 14.1-73.46 FIPS and later - Citrix (Cloud Software Group) — NetScaler ADC 13.1-FIPS and 13.1-NDcPP
Vulnerable versions: 13.1-37.279 through 13.1-37.282
Fixed in: 13.1-37.283 and later
Remediation for Citrix NetScaler ADC and Gateway Critical Memory Overflow
Patches
- Upgrade to 14.1-73.46 or later (14.1 branch)
- Upgrade to 13.1-64.29 or later (13.1 branch)
- Upgrade NetScaler ADC 14.1-FIPS to 14.1-73.46 FIPS or later
- Upgrade NetScaler ADC 13.1-FIPS and NDcPP to 13.1-37.283 or later
Immediate actions
- Inventory NetScaler ADC and Gateway appliances and check the running config for 'add authentication samlAction' (SAML SP) and 'add authentication samlIdPProfile' (SAML IdP)
- Prioritize patching internet-facing appliances configured as SAML IdP or SP
- Review appliance and authentication logs for crashes, unexpected restarts and anomalous requests to SAML endpoints
Workarounds
- Citrix publishes no workaround beyond patching; appliances without a SAML SP or IdP configuration are not affected
Longer-term hardening
- Restrict management and SAML endpoint exposure where architecture allows
- Forward NetScaler logs to the SIEM and alert on core dumps, process restarts and anomalous SAML traffic
- Track NetScaler advisories CTX697096, CTX697190 and CTX697191 as a recurring patch cadence
CVEs associated with Citrix NetScaler ADC and Gateway Critical Memory Overflow
Weaknesses (CWE) in Citrix NetScaler ADC and Gateway Critical Memory Overflow
Timeline of Citrix NetScaler ADC and Gateway Critical Memory Overflow
- CVE-2026-19490, a NetScaler authentication-bypass vulnerability, is added to the CISA KEV catalog, an earlier sign of 2026 NetScaler targeting
- Related NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 surfaced following a Dutch NCSC-NL pre-notification (related context, not this CVE).
- Citrix publishes advisory CTX697096 fixing eight NetScaler ADC/Gateway flaws; CVE-2026-88771 and CVE-2026-88772 are added to CISA KEV the same day
- CVE-2026-88779, a NetScaler SAML memory overflow (CVSS 8.7, DoS) reported by Bishop Fox and watchTowr and exploited in targeted attacks, is added to CISA KEV
- Federal remediation deadline for CVE-2026-88779 per CISA KEV
- CVE-2026-107406 is published in NVD with CVSS v4.0 vector and affected version ranges
- Citrix publishes security bulletin CTX697191 for CVE-2026-107406 (CVSS v4.0 9.5) with fixed builds 14.1-73.46, 13.1-64.29 and 13.1-37.283
- Cyber Security News, SecurityOnline and Cryptika report the flaw; Citrix states it is not aware of unmitigated exploits and no PoC or IOCs are published
Update history for TL-2026-3078
- 2026-10-09 — Citrix NetScaler ADC/Gateway SAML Memory Overflow RCE/DoS (CVE-2026-107406, CVSS v4.0 9.5): What changed No severity, exploitability or status change. Exploitability remains NONE and status remains ACTIVE; the newer report's THEORETICAL/PATCHED values are not escalations and are not applied. New indicators (2) Two SAML configurati
Sources cited for Citrix NetScaler ADC and Gateway Critical Memory Overflow
- Citrix Security Bulletin CTX697191
- Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability (Cyber Security News)
- NVD - CVE-2026-107406
- Citrix Warns of Critical NetScaler SAML Flaw CVE-2026-107406 That Can Lead to Remote Code Execution (SecurityOnline)
- CVE-2026-107406 - Exploits & Severity (Feedly)
- Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability (Cryptika)
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline (related CVE-2026-88779)
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-3078
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3078 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.