Full Report
No word on exploitation status, but a 9.5 severity score suggests time is of the essence
Analysis Summary
# Vulnerability: Citrix NetScaler SAML Memory Buffer Overflow
## CVE Details
- **CVE ID:** CVE-2026-107406
- **CVSS Score:** 9.5 (Critical) - CVSS v4.0
- **CWE:** CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
## Affected Systems
- **Products:** NetScaler ADC, NetScaler Gateway, and Secure Private Access Hybrid deployments.
- **Versions:** Multiple builds are affected (Specific build numbers are referenced in Citrix Advisory CTX697191).
- **Configurations:**
- **Older builds:** Vulnerable when configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP).
- **Recent builds:** Vulnerable specifically when configured as a SAML Identity Provider (IdP).
## Vulnerability Description
The flaw is a memory buffer overflow (CWE-119) occurring within the SAML implementation of Citrix NetScaler. By sending specially crafted SAML messages to a vulnerable instance, an unauthenticated attacker can trigger an improper restriction of operations within a memory buffer. This can lead to memory corruption, resulting in either a Denial of Service (DoS) crash or Remote Code Execution (RCE) with the privileges of the NetScaler process.
## Exploitation
- **Status:** No confirmed exploitation in the wild at the time of publication (Note: A separate flaw, CVE-2026-6185, was noted as actively exploited, increasing the urgency for this 9.5 rated patch).
- **Complexity:** Low to Medium (depending on the target configuration).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential for RCE and data theft).
- **Integrity:** High (System takeover).
- **Availability:** High (Denial of Service).
## Remediation
### Patches
Citrix has released updated builds for NetScaler ADC and NetScaler Gateway. Administrators must update to the following versions (or newer) as specified in the vendor advisory:
- NetScaler ADC and NetScaler Gateway 14.1
- NetScaler ADC and NetScaler Gateway 13.1
- NetScaler ADC and NetScaler Gateway 13.0
- NetScaler ADC 13.1-FIPS
- NetScaler ADC 12.1-FIPS
- NetScaler ADC 12.1-NDcPP
*Note: Citrix manages updates for Cloud Services and Adaptive Authentication; no customer action is required for those managed services.*
### Workarounds
- No specific workarounds were provided in the report other than patching. Organizations not using SAML configurations may have a lower risk profile, but patching remains the recommended course of action.
## Detection
- **Indicators of Compromise:** Monitor for unusual crash logs in the NetScaler process (NSPPE) or unexpected outbound traffic from NetScaler management interfaces.
- **Detection methods:** Review system logs for SAML assertion errors or segmentation faults that correlate with external requests.
## References
- Citrix Advisory: hxxps[://]support[.]citrix[.]com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale[.]html
- Original Article: hxxps[://]www[.]theregister[.]com/2026/10/09/citrix_netscaler_critical_patch/ (Defanged based on context)