# Citrix NetScaler ADC and Gateway Critical Memory Overflow RCE in SAML SP/IdP Configurations (CVE-2026-107406)

> Citrix disclosed CVE-2026-107406 (CVSS v4.0 9.5), a memory overflow in NetScaler ADC and NetScaler Gateway that may lead to remote code execution or denial of service when the appliance is configured as a SAML Service Provider or Identity Provider. Citrix is not aware of unmitigated exploits at publication; patched builds are available.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T07:37:52.267Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3078
- **ID:** TL-2026-3078
- **Severity:** CRITICAL (CVSS 9.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-107406

## Description

CVE-2026-107406 is a memory overflow (classified in reporting as CWE-119, improper restriction of operations within the bounds of a memory buffer) in NetScaler ADC and NetScaler Gateway, published 2026-10-08 in Citrix security bulletin CTX697191. Successful exploitation may lead to remote code execution or denial of service. NVD records the CVSS v4.0 vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L (base score 9.5): network-reachable, no privileges or user interaction required, high attack complexity.

Exposure depends on SAML configuration. On builds before 14.1-73.37 and 13.1-64.23, the appliance is vulnerable when configured as either a SAML Service Provider (SP) or SAML Identity Provider (IdP). On the newer builds 14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28 (and the corresponding FIPS/NDcPP builds), the flaw applies only when the appliance is configured as a SAML IdP. Appliances without SAML configuration are not affected. Defenders can identify exposure by looking for 'add authentication samlAction' (SAML SP role) and 'add authentication samlIdPProfile' (SAML IdP role) in the running configuration. Secure Private Access hybrid deployments using NetScaler are affected; Citrix-managed cloud services and Adaptive Authentication are reported as unaffected.

At publication Citrix stated it was not aware of any unmitigated exploits; no public proof-of-concept, no named threat actors and no indicators of compromise have been reported. The finding was credited to Michael Tucker, Chew Keong Tan, Alex Bernier (JPMorgan Chase XOR Team) and Maxim Suhanov. Context for prioritization: NetScaler has been repeatedly exploited in 2026, and a closely related SAML memory overflow, CVE-2026-88779 (CVSS 8.7, DoS, reported by Bishop Fox and watchTowr), was added to CISA KEV on 2026-10-04 after targeted exploitation. CVE-2026-107406 is a separate CVE and was not listed in the KEV content reviewed. The ATT&CK mappings below are anticipated attacker behaviors for an internet-facing appliance memory-corruption flaw, not observed activity.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1595.002 Active Scanning: Vulnerability Scanning
- T1587.004 Develop Capabilities: Exploits

## Sources

- [Citrix Security Bulletin CTX697191](https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191)
- [Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability (Cyber Security News)](https://cybersecuritynews.com/citrix-netscaler-adc-and-gateway-rce/)
- [NVD - CVE-2026-107406](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-107406)
- [Citrix Warns of Critical NetScaler SAML Flaw CVE-2026-107406 That Can Lead to Remote Code Execution (SecurityOnline)](https://securityonline.info/citrix-netscaler-vulnerability-cve-2026-107406/)
- [CVE-2026-107406 - Exploits & Severity (Feedly)](https://feedly.com/cve/CVE-2026-107406)
- [Citrix Urges NetScaler ADC and Gateway Customers to Patch for New Critical RCE Vulnerability (Cryptika)](https://www.cryptika.com/citrix-urges-netscaler-adc-and-gateway-customers-to-patch-for-new-critical-rce-vulnerability/)
- [New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline (related CVE-2026-88779)](https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3078
