📢 New: Continuous AI Pentesting. Always-on, across all exposed assets. Learn more 📢 New: Continuous AI Pentesting.
Back to Blog

Emerging Threat: (CVE-2026-107406) NetScaler ADC and Gateway Remote Code Execution via SAML

Sample of assets impacted by NetScaler vulnerability, identified by the CyCognito Platform


What is CVE-2026-107406?

CVE-2026-107406 is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway, classified as CWE-119. Successful exploitation leads to remote code execution or denial of service.

The vulnerability carries a CVSS v4.0 base score of 9.5 (Critical). Attack vector is network, and neither privileges nor user interaction are required. Confidentiality, integrity, and availability impacts are rated high on the vulnerable system, and confidentiality and integrity are rated high on subsequent systems as well.

Attack complexity is rated high, which is the one factor holding the score below the maximum. CISA’s vulnrichment entry records exploitation as none observed and automatable as no, while rating technical impact as total. Citrix stated at disclosure that it was not aware of unmitigated exploits, and no public proof of concept had been identified at publication.

The device class is what makes this serious regardless of complexity. NetScaler ADC and Gateway sit at the network edge and terminate remote access for the applications behind them. Code execution on the appliance is not code execution on one server, it is control of the device that brokers authentication for everything it fronts. This product line has a history of flaws that moved from advisory to mass exploitation quickly once an exploit became public.

What assets are affected by CVE-2026-107406?

Exposure depends on configuration as much as on version, and the two interact in a way that makes this advisory harder to read than most.

The appliance must be configured as a SAML service provider or a SAML identity provider. For builds from 14.1-73.37 through 14.1-73.41, and from 13.1-64.23 through 13.1-64.28, along with their FIPS equivalents, only the identity provider role is affected. For anything older than 14.1-73.37 or 13.1-64.23, either role is affected. An appliance doing plain load balancing with no SAML authentication configured is not in scope.

Citrix points administrators at two configuration entries to check: add authentication samlAction for service provider configuration and add authentication samlIdPProfile for identity provider configuration. That check, run per appliance, is what separates a list of NetScaler hostnames from a list of actually affected devices.

In practice an affected asset is an internet-facing NetScaler terminating remote access, VPN replacement, or application access for a workforce. These appliances exist to be reachable, so unlike most emerging threats there is no question of whether exposure is intentional. The question is only which role the device plays and which build it runs.

Externally, the build number is not visible and neither is the SAML configuration. A scan identifies the appliance, not its scope.

What does our data show about exposure patterns?

Exposure in this set is led by Industrials at 26.2% of observed assets, with Financials contributing 11.2% and Health Care 10.3%. The remaining sectors together account for 52.4%.

That ordering reflects which organizations buy this class of appliance. NetScaler is remote access infrastructure for large distributed workforces, so the footprint follows organizations with many sites, many remote staff, and a regulatory reason to terminate access on equipment they control rather than in a cloud service. Professional services firms, banks, insurers, and hospital groups all sit squarely in that description.

Concentration is moderate here. The largest estate accounts for roughly an eighth of the observed assets, which is lower than the heavily skewed sets but higher than the broad software footprints, so the sector shares carry real signal without being free of estate effects.

This set has the weakest version evidence of any recent exposure data. Every observed asset is fingerprint-level, with no high-confidence version detections at all, and a build number appears in the service record only rarely. For a vulnerability whose scope is defined by narrow build ranges, that means external data cannot distinguish an affected appliance from a patched one.

One signal does narrow the field usefully. Close to three in ten of the observed assets present a NetScaler AAA login panel, which means they are running authentication virtual servers rather than serving plain load balancing. That is not evidence of SAML, and it should not be read as such, but SAML service provider and identity provider configurations live inside exactly that authentication layer. Those appliances are where a configuration review should start.

The broader point is that this is the device class where the gap between running the software and being exposed is narrowest. A forgotten Jira instance might be unreachable. A NetScaler Gateway is reachable by design, which is why the configuration check matters more than the usual inventory sweep.

Are fixes available?

Yes. Citrix has released fixed builds for every affected line. NetScaler ADC and Gateway on the 14.1 line should move to 14.1-73.46 or later, and on the 13.1 line to 13.1-64.29 or later. The FIPS variants have their own targets: 14.1-73.46 FIPS, and 13.1-37.283 for the 13.1 FIPS and NDcPP branch, which uses a different build numbering scheme from the main 13.1 line and is easy to misread.

Citrix has published no workaround. Because the exposure follows from the SAML configuration rather than from an optional feature that can simply be switched off, there is no mitigation short of upgrading, beyond removing SAML authentication entirely where it is not required.

Appliances past end of life are not covered by these fixes and will not receive one. Those need migration to a supported version rather than patching, which is a project rather than a maintenance window and should be started now rather than scheduled later.

Organizations running Secure Private Access in a hybrid deployment need to update the underlying NetScaler instances themselves. Citrix-managed cloud services and Adaptive Authentication are handled by Cloud Software Group and need no customer action.

Until patching is confirmed, defenders should:

  • Inventory every internet-facing NetScaler ADC and Gateway appliance with its exact build
  • Check each appliance for add authentication samlAction and add authentication samlIdPProfile
  • Prioritise appliances presenting an authentication login panel over plain load balancers
  • Identify end-of-life appliances that cannot receive a fix and plan migration
  • Investigate unexplained appliance crashes or restarts on SAML-facing virtual servers
  • Monitor externally reachable authentication endpoints for abnormal request patterns

How can CyCognito help your organization?

CyCognito published an Emerging Threat Advisory for CVE-2026-107406 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.

To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.


Request a free scan

See Exactly What Attackers See

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally .

Request a Scan
Top Attack Paths