The essentials
- On 9 October 2026, CERT-FR issued advisory CERTFR-2026-AVI-1285 on a Citrix NetScaler ADC and Gateway flaw (bulletin CTX697191), citing remote code execution and remote denial of service.
- Affected NetScaler ADC and Gateway 13.1.x and 14.1.x releases—including FIPS and 13.1-NDcPP lines below thresholds such as 13.1-64.29, 14.1-73.46, and related FIPS builds—are listed in the official advisory.
- Citrix describes CVE-2026-107406 as a critical memory overflow (CVSS v4.0: 9.5) when the appliance acts as a SAML SP or IdP; newer builds that fixed earlier CVEs may still be exposed depending on the SAML role.
What CERT-FR reports
On 9 October 2026, France’s CERT-FR published advisory CERTFR-2026-AVI-1285 on a vulnerability in Citrix NetScaler ADC and NetScaler Gateway. It references vendor bulletin CTX697191 from the same day. The official summary cites arbitrary remote code execution and remote denial of service.
Scope spans 13.1 and 14.1 release families, including FIPS and 13.1-NDcPP variants with distinct fixed-build floors. The advisory lists, for example, NetScaler ADC 14.1.x before 14.1-73.46, 13.1.x before 13.1-64.29, plus FIPS thresholds (14.1-73.46 FIPS, 13.1-NDcPP 13.1.37.283, and others). Teams should match displayed build numbers with SAML role before closing a patch ticket.
SAML: when the flaw applies
In its 8 October 2026 guidance blog, Citrix states that CVE-2026-107406 is a memory overflow that may lead to code execution or denial of service under specific configuration. The appliance must serve as a SAML identity provider (IdP) or service provider (SP); depending on the build range, only the IdP role or both roles are in scope. Citrix explains checking for `samlAction` (SP) or `samlIdPProfile` (IdP) entries in the configuration.
- Inventory NetScaler instances used as VPN/ADC front ends and Secure Private Access Hybrid deployments flagged by the vendor.
- Flag appliances using SAML authentication (SSO to line-of-business apps, partner federation).
- Schedule upgrades to 14.1-73.46 or 13.1-64.29 (or FIPS/NDcPP builds listed in CTX697191), even if a recent fix for another CVE was already applied.
Severity and known exploitation
Citrix rates the issue Critical and publishes a CVSS v4.0 base score of 9.5 in its official blog. At bulletin publication, the vendor states it is not aware of unmitigated exploitation of this vulnerability. CERT-FR points to the vendor bulletin for patches; the French advisory does not document a workaround.
For teams that rely on NetScaler at the edge
NetScaler often terminates remote access (Gateway) or TLS in front of internal applications. An RCE on an Internet-facing component, combined with widely deployed SAML sign-on, calls for a short patch SLA and clear communication to SSO-dependent business units. 12.1 and 13.0 branches are end of life on the vendor side: they are not listed in the CERT-FR matrix, but an unmigrated appliance remains a structural risk.
Sources
- Vulnérabilité dans Citrix NetScaler ADC et GatewayANSSI — CERT-FR · 9 October 2026
- Citrix NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-107406 (CTX697191)Citrix · 9 October 2026
- Protecting Customers: Immediate Guidance for CVE-2026-107406Citrix Community — NetScaler Cyber Threat Intelligence · 8 October 2026
This note was drafted with AI tools from the cited sources, then reviewed and published under the responsibility of Jordan FOUASSIER, publication director. We summarise the facts and add our reading; source text and images are not reproduced. An error? Write to contact@aigyrosgroup.com.