we_are_coded.by CODE · The world, decoded
БГ
Citrix

New critical NetScaler hole with SAML, CVE-2026-107406: the fix is 14.1-73.46 or 13.1-64.29

Citrix CTX697191 (CVE-2026-107406) · event date: 8 October 2026Security

Citrix issued bulletin CTX697191 on 8 October: a memory overflow rated 9.5 that leads to code execution or denial of service. NetScaler configured as a SAML SP or IdP is affected, and for IdP the versions from the last two upgrades are on the list too. The bulletin does not mention exploitation.

In short
  • 8 October 2026: Citrix issues bulletin CTX697191 for CVE-2026-107406 in NetScaler ADC and Gateway. Memory overflow (CWE-119), code execution or denial of service, CVSS v4.0 9.5.
  • Condition: the appliance is configured as a SAML SP or SAML IdP. For IdP, 14.1-73.37 to 14.1-73.41 and 13.1-64.23 to 13.1-64.28 are affected too; for SP or IdP, everything before 14.1-73.37 and 13.1-64.23 is affected.
  • The fixes: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 for FIPS and NDcPP. The bulletin does not say the hole is being exploited; NVD has not scored it yet.
Checked on9 October 2026Responsible editorCvetelin IvanovHow we workMethod · Corrections

14.1-73.41 was the version we sent you to on 4 October. If your NetScaler is configured as a SAML IdP, today it is on the affected list.

The facts: on 8 October 2026 Citrix published security bulletin CTX697191, severity Critical, for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway. The vulnerability is a memory overflow (CWE-119) that leads to remote code execution or denial of service; CVSS v4.0 9.5. Condition: NetScaler must be configured as a SAML SP or SAML IdP. Only when configured as an IdP, versions 14.1-73.37 through 14.1-73.41 inclusive and 13.1-64.23 through 13.1-64.28 inclusive are affected, plus the matching FIPS and NDcPP versions; as an SP or an IdP, every version before 14.1-73.37 and before 13.1-64.23 is affected. Secure Private Access Hybrid deployments that use NetScaler are affected too. The fixes are 14.1-73.46 and later, 13.1-64.29 and later releases of 13.1, 14.1-73.46 FIPS, and 13.1-37.283 for FIPS and NDcPP. The bulletin applies only to customer-managed installations; Citrix upgrades its own cloud services. Citrix thanks Joshua Foote, Michael Tucker and Eugene Lim of the XOR Team at JPMorgan Chase for working with it. The bulletin does not say whether the vulnerability is being exploited. In the US National Vulnerability Database the record is already published, but NVD has not provided its own assessment yet.

Two questions settle everything. Is there SAML on your NetScaler. And if there is, in what role: as an SP it accepts a login verified elsewhere, as an IdP it verifies people for other applications itself.

The bulletin gives a check in the configuration. A line add authentication samlAction means SP. A line add authentication samlIdPProfile means IdP. If you have neither, Citrix's condition is not met.

Two lines in the configuration decide whether this hole is yours.

Here is the unpleasant part. If you are on 14.1-73.37 to 73.41 or on 13.1-64.23 to 64.28, the hole is yours only as an IdP. If you are older, it is yours as an SP too. The versions the previous two bulletins sent people to do not suffice for anyone who runs an IdP.

What I still do not know. The bulletin does not mention exploitation. That does not mean there is none. I could not open Citrix's additional guidance in its community, the server returned an access denial, so I do not quote it.

The target is now 14.1-73.46 or 13.1-64.29, and for FIPS 14.1-73.46 FIPS or 13.1-37.283. First the two lines in the configuration, then the version.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Citrix CTX697191 (CVE-2026-107406), 08.10.2026→NVD - CVE-2026-107406, record as of 09.10.2026
Original: https://wearecoded.com/en/articles/citrix-netscaler-cve-2026-107406-saml-treto-nadgrazhdane.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news