Citrix issued bulletin CTX697191 on 8 October: a memory overflow rated 9.5 that leads to code execution or denial of service. NetScaler configured as a SAML SP or IdP is affected, and for IdP the versions from the last two upgrades are on the list too. The bulletin does not mention exploitation.
- 8 October 2026: Citrix issues bulletin CTX697191 for CVE-2026-107406 in NetScaler ADC and Gateway. Memory overflow (CWE-119), code execution or denial of service, CVSS v4.0 9.5.
- Condition: the appliance is configured as a SAML SP or SAML IdP. For IdP, 14.1-73.37 to 14.1-73.41 and 13.1-64.23 to 13.1-64.28 are affected too; for SP or IdP, everything before 14.1-73.37 and 13.1-64.23 is affected.
- The fixes: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 for FIPS and NDcPP. The bulletin does not say the hole is being exploited; NVD has not scored it yet.
14.1-73.41 was the version we sent you to on 4 October. If your NetScaler is configured as a SAML IdP, today it is on the affected list.
Two questions settle everything. Is there SAML on your NetScaler. And if there is, in what role: as an SP it accepts a login verified elsewhere, as an IdP it verifies people for other applications itself.
The bulletin gives a check in the configuration. A line add authentication samlAction means SP. A line add authentication samlIdPProfile means IdP. If you have neither, Citrix's condition is not met.
Here is the unpleasant part. If you are on 14.1-73.37 to 73.41 or on 13.1-64.23 to 64.28, the hole is yours only as an IdP. If you are older, it is yours as an SP too. The versions the previous two bulletins sent people to do not suffice for anyone who runs an IdP.
What I still do not know. The bulletin does not mention exploitation. That does not mean there is none. I could not open Citrix's additional guidance in its community, the server returned an access denial, so I do not quote it.
The target is now 14.1-73.46 or 13.1-64.29, and for FIPS 14.1-73.46 FIPS or 13.1-37.283. First the two lines in the configuration, then the version.