Threat reportVulnerabilityTL-2026-3078

Citrix NetScaler ADC and Gateway Critical Memory Overflow RCE in SAML SP/IdP Configurations (CVE-2026-107406)

criticalACTIVE

Citrix NetScaler ADC and Gateway Critical Memory Overflow (TL-2026-3078), also tracked as CTX697191, is a critical-severity software vulnerability scored CVSS 9.5, first published 2026-10-09. It has no confirmed attribution, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway 14.1, references 1 CVE (CVE-2026-107406), maps to 5 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 14 indicators of compromise.

CVSS
9.5/10Critical
CVEs
1Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-3078

Threat ID
TL-2026-3078
Also known as
CTX697191
Severity
CRITICAL
CVSS
9.5 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, telecoms, education
Target regions
Global
Detection rules
9
Indicators of compromise
14
Updates
2026-10-09 · revalidated 1× · latest source

How Citrix NetScaler ADC and Gateway Critical Memory Overflow works

Citrix disclosed CVE-2026-107406 (CVSS v4.0 9.5), a memory overflow in NetScaler ADC and NetScaler Gateway that may lead to remote code execution or denial of service when the appliance is configured as a SAML Service Provider or Identity Provider. Citrix is not aware of unmitigated exploits at publication; patched builds are available.

CVE-2026-107406 is a memory overflow (classified in reporting as CWE-119, improper restriction of operations within the bounds of a memory buffer) in NetScaler ADC and NetScaler Gateway, published 2026-10-08 in Citrix security bulletin CTX697191. Successful exploitation may lead to remote code execution or denial of service. NVD records the CVSS v4.0 vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L (base score 9.5): network-reachable, no privileges or user interaction required, high attack complexity.

Exposure depends on SAML configuration. On builds before 14.1-73.37 and 13.1-64.23, the appliance is vulnerable when configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). On the newer builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 (and the corresponding FIPS/NDcPP builds), the flaw applies only when the appliance is configured as a SAML IdP. Appliances without SAML configuration are not affected. Defenders can identify exposure by looking for 'add authentication samlAction' (SAML SP role) and 'add authentication samlIdPProfile' (SAML IdP role) in the running configuration. Secure Private Access hybrid deployments using NetScaler are affected; Citrix-managed cloud services and Adaptive Authentication are reported as unaffected.

At publication Citrix stated it was not aware of any unmitigated exploits; no public proof-of-concept, no named threat actors and no indicators of compromise have been reported. The finding was credited to Michael Tucker, Chew Keong Tan, Alex Bernier (JPMorgan Chase XOR Team) and Maxim Suhanov. Context for prioritization: NetScaler has been repeatedly exploited in 2026, and a closely related SAML memory overflow, CVE-2026-88779 (CVSS 8.7, DoS, reported by Bishop Fox and watchTowr), was added to CISA KEV on 2026-10-04 after targeted exploitation. CVE-2026-107406 is a separate CVE and was not listed in the KEV content reviewed. The ATT&CK mappings below are anticipated attacker behaviors for an internet-facing appliance memory-corruption flaw, not observed activity.

MITRE ATT&CK techniques used in TL-2026-3078

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Resource Development

T1587.004 Develop Capabilities: Exploits

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in Citrix NetScaler ADC and Gateway Critical Memory Overflow

  • Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway 14.1
    Vulnerable versions: 14.1-73.37 through 14.1-73.41 (SAML IdP only); builds before 14.1-73.37 (SAML SP or IdP)
    Fixed in: 14.1-73.46 and later
  • Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway 13.1
    Vulnerable versions: 13.1-64.23 through 13.1-64.28 (SAML IdP only); builds before 13.1-64.23 (SAML SP or IdP)
    Fixed in: 13.1-64.29 and later
  • Citrix (Cloud Software Group) — NetScaler ADC 14.1-FIPS
    Vulnerable versions: 14.1-73.37 through 14.1-73.41
    Fixed in: 14.1-73.46 FIPS and later
  • Citrix (Cloud Software Group) — NetScaler ADC 13.1-FIPS and 13.1-NDcPP
    Vulnerable versions: 13.1-37.279 through 13.1-37.282
    Fixed in: 13.1-37.283 and later

Remediation for Citrix NetScaler ADC and Gateway Critical Memory Overflow

Patches

  • Upgrade to 14.1-73.46 or later (14.1 branch)
  • Upgrade to 13.1-64.29 or later (13.1 branch)
  • Upgrade NetScaler ADC 14.1-FIPS to 14.1-73.46 FIPS or later
  • Upgrade NetScaler ADC 13.1-FIPS and NDcPP to 13.1-37.283 or later

Immediate actions

  • Inventory NetScaler ADC and Gateway appliances and check the running config for 'add authentication samlAction' (SAML SP) and 'add authentication samlIdPProfile' (SAML IdP)
  • Prioritize patching internet-facing appliances configured as SAML IdP or SP
  • Review appliance and authentication logs for crashes, unexpected restarts and anomalous requests to SAML endpoints

Workarounds

  • Citrix publishes no workaround beyond patching; appliances without a SAML SP or IdP configuration are not affected

Longer-term hardening

  • Restrict management and SAML endpoint exposure where architecture allows
  • Forward NetScaler logs to the SIEM and alert on core dumps, process restarts and anomalous SAML traffic
  • Track NetScaler advisories CTX697096, CTX697190 and CTX697191 as a recurring patch cadence

CVEs associated with Citrix NetScaler ADC and Gateway Critical Memory Overflow

CVE-2026-107406

Weaknesses (CWE) in Citrix NetScaler ADC and Gateway Critical Memory Overflow

CWE-119

Timeline of Citrix NetScaler ADC and Gateway Critical Memory Overflow

  • CVE-2026-19490, a NetScaler authentication-bypass vulnerability, is added to the CISA KEV catalog, an earlier sign of 2026 NetScaler targeting
  • Related NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 surfaced following a Dutch NCSC-NL pre-notification (related context, not this CVE).
  • Citrix publishes advisory CTX697096 fixing eight NetScaler ADC/Gateway flaws; CVE-2026-88771 and CVE-2026-88772 are added to CISA KEV the same day
  • CVE-2026-88779, a NetScaler SAML memory overflow (CVSS 8.7, DoS) reported by Bishop Fox and watchTowr and exploited in targeted attacks, is added to CISA KEV
  • Federal remediation deadline for CVE-2026-88779 per CISA KEV
  • CVE-2026-107406 is published in NVD with CVSS v4.0 vector and affected version ranges
  • Citrix publishes security bulletin CTX697191 for CVE-2026-107406 (CVSS v4.0 9.5) with fixed builds 14.1-73.46, 13.1-64.29 and 13.1-37.283
  • Cyber Security News, SecurityOnline and Cryptika report the flaw; Citrix states it is not aware of unmitigated exploits and no PoC or IOCs are published

Update history for TL-2026-3078

Sources cited for Citrix NetScaler ADC and Gateway Critical Memory Overflow

Detection coverage for TL-2026-3078

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3078 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats