Critical Remote Code Execution Vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-107406)
Executive Summary
On October 8th, 2026, Citrix disclosed a critical vulnerability in NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-107406, the flaw is a memory overflow that can lead to remote code execution (RCE) or denial of service on appliances when the appliance is configured to act as a SAML identity provider. Citrix has released a new fix for the vulnerability. See our Affected Systems or Products table for more information.
NetScaler ADC and NetScaler Gateway are internet-facing appliances that provide application delivery, VPN, and single sign-on access across enterprise environments. NetScaler has faced sustained attacks in recent weeks, with threat actors exploiting two RCE vulnerabilities as zero-days in late September, followed days later by exploitation of a separate SAML flaw to disrupt authentication services.
Citrix states it is not aware of exploitation at the time of its bulletin, and no public proof-of-concept (PoC) is known at the time of writing. Given the critical impact, the SAML attack surface already targeted this month, and the rapid weaponization of recent NetScaler flaws, Beazley Security recommends affected organizations apply available fixes as soon as possible.
Affected Systems or Products
Mitigations / Workarounds
Citrix recommends affected customers upgrade to the fixed builds listed in its security bulletin, and its published guidance for this vulnerability does not describe a workaround. Citrix identifies exposed appliances by their SAML configuration. Administrators can review the running configuration for either of the following entries:
add authentication samlAction # appliance is configured as a SAML service provider (SP)
add authentication samlIdPProfile # appliance is configured as a SAML identity provider (IdP)If patching cannot be immediately applied, the following may help to temporarily reduce risk:
- Remove SAML IdP or SP configurations that are no longer in use, since appliances without them do not meet the vulnerability's preconditions.
- Restrict access to Gateway and AAA virtual servers that use SAML authentication to trusted networks where operationally feasible.
- Monitor appliances for unexplained crashes of the authentication service or unexpected reboots, and preserve logs and configuration if either occurs.
Patches
Citrix has released fixed builds for all supported NetScaler ADC and NetScaler Gateway branches, and details are in the official Citrix security bulletin. Citrix upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication itself, so those require no customer action.
Technical Details
CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway that Citrix states may lead to remote code execution or denial of service when the appliance is configured to act as a SAML identity provider. Citrix has provided limited technical details about the latest flaw, and no independent technical analysis or public PoC is known at the time of writing.
This is the second SAML-related NetScaler flaw disclosed in a week. CVE-2026-88779, a memory overflow in SAML processing on appliances configured as a SAML SP or IdP, was exploited as a zero-day to crash authentication services and force appliance reboots, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on October 4th, 2026. Citrix has not stated whether CVE-2026-107406 is related to CVE-2026-88779 beyond the shared SAML preconditions.
On September 27, 2026, Citrix disclosed eight NetScaler vulnerabilities, including CVE-2026-88771 (unauthenticated command execution) and CVE-2026-88772 (memory overflow when DTLS is enabled). Both were exploited as zero-days and added to CISA’s KEV catalog the same day. Beazley Security previously reported on active exploitation in the wild and logged several indicators of compromise associated with these campaigns. Organizations exposed to these flaws should assess for compromise in addition to upgrading to address CVE-2026-107406.
How Beazley Security is Responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this vulnerability and need support, please contact our Incident Response team.
Sources
- NVD: CVE-2026-107406
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin (CTX697191)
- Citrix: Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway
- BSL: Citrix NetScaler Vulnerabilities Under Active Exploitation (CVE-2026-88771, CVE-2026-88772, & CVE-2026-88779)
- IFIN: CVE-2026-107406: Somehow, Another Citrix Netscaler SAML Vulnerability
- CISA: Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway
- LevelBlue: Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators
Aware of an incident impacting your industry? Let us know: