The Fix Became the Affected Version: NetScaler CVE-2026-107406 and the Third Upgrade in Eleven Days
Citrix bulletin CTX697191 was created on 8 October 2026 at 20:28 and last modified 9 October at 11:18. It discloses one vulnerability, CVE-2026-107406, in NetScaler ADC and NetScaler Gateway: a memory overflow leading to remote code execution or denial of service, CWE-119, CVSS 4.0 base score 9.5, vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L. The precondition is SAML: the appliance must be configured as a SAML service provider or a SAML identity provider.
That precondition is familiar, and so is the bug class. But the affected-versions table is where this advisory stops being routine. Read it carefully, because it does something a vendor bulletin almost never does — it names its own previous patch as vulnerable.
The remediation we published five days ago is now an affected build
On 5 October we covered CVE-2026-88779, a SAML memory overflow that CISA added to KEV on 4 October with a three-day remediation deadline, and whose fix was 14.1-73.41 and 13.1-64.28 (plus 14.1-73.41 FIPS and 13.1-37.282). Those were the builds eight days after a first emergency round had already pushed everyone to 14.1-73.37 and 13.1-64.23.
CTX697191 splits its scope into two tiers. Tier one, applicable only when configured as a SAML IdP:
- NetScaler ADC and Gateway between 14.1-73.37 and 14.1-73.41, inclusive
- NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive
- NetScaler ADC and Gateway between 13.1-64.23 and 13.1-64.28, inclusive
- NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1-37.282, inclusive
Tier two, applicable when configured as a SAML SP or SAML IdP: everything before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-NDcPP 13.1-37.279.
Set those side by side and the structure is explicit. The upper bound of tier one is the fixed build from the 88779 bulletin. The lower bound is the fixed build from the 88771/88772 bulletin. Every release that was correct remediation advice between 27 September and 8 October sits inside the IdP-only affected range. An administrator who did exactly what three agencies and one vendor told them to do — twice, at speed, during a KEV deadline — is affected today, and is affected because they patched.
The new fixed builds are 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1-37.283 for 13.1-FIPS and 13.1-NDcPP. Secure Private Access Hybrid deployments on customer-managed NetScaler instances are in scope; Citrix-managed cloud services and Citrix-managed Adaptive Authentication are handled by Cloud Software Group.
Why the split matters operationally
The two-tier table is not bureaucratic formatting — it is a triage instruction, and most asset inventories cannot answer it. If your appliance is a SAML service provider only (it consumes assertions from Entra ID, Okta, Ping) and you are already on 14.1-73.41 or 13.1-64.28, you are outside tier one. If it is a SAML identity provider (it issues assertions to downstream applications), being fully patched as of last week buys you nothing here.
Citrix publishes the exact configuration check, and it is the same pair of commands as the 88779 bulletin:
# Appliance is configured as a SAML SP
add authentication samlAction
# Appliance is configured as a SAML IdP
add authentication samlIdPProfile
Run both. The answer determines not whether you patch but how fast: SP-only on a current build is a scheduled change, IdP on any build is an unscheduled one. We would still patch both — the version-specific carve-out is a vendor's statement about reachability, not a guarantee about an attacker's creativity — but the distinction is how you decide what happens tonight versus next week.
Reading the vector, not the number
The 9.5 and the 8.7 from 88779 come from different places, and the difference is the story. CVE-2026-88779 carried VC:N/VI:N/VA:H — Citrix asserting no confidentiality or integrity impact, availability only. A crash. CVE-2026-107406 carries VC:H/VI:H/VA:H plus subsequent-system impacts SC:H/SI:H/SA:L, which is the vendor's own statement that the same memory-safety surface now yields code execution and that the blast radius leaves the appliance.
The one element arguing the other way is AC:H, high attack complexity. That is what keeps this from being a 10.0 and it is presumably why the score is 9.5 rather than higher despite unauthenticated network reach. Treat AC:H as a statement about the first working exploit's difficulty, not about the second one's: this is the fourth NetScaler SAML-adjacent memory bug in eleven days, and the preceding two were exploited as zero-days against government, financial services, education, legal, and professional services organisations before any advisory existed.
Current status, as of writing: Citrix states it is not aware of any unmitigated exploits of CVE-2026-107406. CVE-2026-107406 is not in the CISA Known Exploited Vulnerabilities catalog — we checked the KEV JSON feed directly (catalogVersion 2026.10.08, 1,739 entries); the NetScaler entries it does carry are 88779 (added 4 October), 88772 and 88771 (both 27 September), CVE-2026-19490, and CVE-2026-8452. The bulletin lists no workaround. There is nothing to toggle off: SAML is either configured or it is not, and if it is, the appliance is doing its job.
Credit goes to Joshua Foote, Michael Tucker, and Eugene Lim of the XOR Team at JPMorgan Chase, per Citrix's acknowledgement section. That is a coordinated-disclosure find from a bank's offensive team, which is the materially better of the two ways this class of bug tends to surface on this class of device.
The pattern worth naming
Three bulletins, eleven days, one subsystem: CTX697096 (27 September, eight CVEs, two exploited zero-days), CTX697174 (3 October, one CVE, KEV in a day), CTX697191 (8 October, one CVE, prior fixes in scope). Each fix landed inside the range of the next. That is the signature of a component under sustained scrutiny — from attackers in the first round, from researchers in the third — where patches are being cut faster than the surrounding code can be audited.
For anyone running agent or AI workloads behind this edge, the exposure is the same as it was in September and has not improved: the appliance terminates the session, validates the assertion, and holds the tokens. Code execution there does not require touching the agent, the model, or the MCP server. It is also the recurring shape of this autumn's edge coverage — SonicWall's 10.0 pre-auth SSRF in the SMA1000 WorkPlace portal three days ago, same category of component, same impossibility of taking it offline.
What to do
- Answer the IdP question first, per appliance. Run both configuration checks. An appliance with
samlIdPProfileon 14.1-73.41 / 13.1-64.28 / 14.1-73.41 FIPS / 13.1-37.282 is affected despite being current as of last week — that is the population most likely to believe it is already done. - Upgrade to 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283. No workaround exists. Confirm which branch and FIPS/NDcPP variant each unit is on before scheduling; the four target builds are not interchangeable.
- Include Secure Private Access Hybrid instances. Customer-managed NetScaler instances behind SPA Hybrid are explicitly in scope and are routinely missed because the service is thought of as Citrix-managed. The Citrix-managed cloud services and Adaptive Authentication are not your job; the instances you run are.
- Do not let “no known exploitation” set the timeline. On this device family, in this window, two of the last ten CVEs were exploited before disclosure and a third hit KEV within 24 hours. Plan the change window on the assumption the status line changes before you finish it.
- Re-open the 27 September incident question if you are an IdP. If the appliance was ever on an affected build with SAML configured, the hunting and evidence-preservation guidance from the zero-day round still applies — patching to 73.46 remediates the flaw, not a prior intrusion.
Verification note: we read Citrix bulletin CTX697191 directly (article record type Security Bulletin, created 10-08-2026 20:28, last modified 10-09-2026 11:18) for the CVE description, the two-tier affected-version table, the CWE-119 classification, the CVSS 4.0 9.5 score and vector, the four fixed builds, the Secure Private Access Hybrid note, the SAML configuration-check commands, and the XOR Team / JPMorgan Chase acknowledgement. We cross-checked the record against the NVD API (CVE-2026-107406, published 2026-10-08T22:17:26.847, status Received, same vector and CWE, both Citrix references), and queried the CISA KEV JSON feed (catalogVersion 2026.10.08, dateReleased 2026-10-08T20:09:18Z, 1,739 entries) to confirm the CVE is absent and to enumerate the existing NetScaler entries. The “not aware of any unmitigated exploits” statement is quoted from Citrix's customer guidance as reported by SecurityWeek (9 October); the Citrix TechZone blog that carries it returned a Cloudflare bot-verification interstitial and could not be read directly, so that line is attributed rather than first-hand. The exploitation history and targeted-sector list for CVE-2026-88771 and CVE-2026-88772 are from our earlier coverage and SecurityWeek's reporting. The prior fixed builds (14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS, 13.1-37.282) are from CTX697174 as recorded in our 5 October briefing. The observation that the previous remediation falls inside the new affected range is our reading of the published version tables, not a Citrix statement. We did not test any appliance and did not attempt exploitation.
Sources:
- Citrix — CTX697191, NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-107406 (affected versions, fixed builds, CVSS vector, acknowledgement)
- NVD — CVE-2026-107406 (published 8 October 2026, CVSS 4.0 9.5, CWE-119)
- CISA — Known Exploited Vulnerabilities catalog (JSON feed, catalogVersion 2026.10.08; CVE-2026-107406 not listed)
- SecurityWeek — Citrix Urges Immediate Patching of Critical NetScaler Vulnerability (9 October 2026; Citrix exploitation statement, prior zero-day targeting)
- Cloud Software Group — Immediate Guidance for CVE-2026-107406 (referenced by CTX697191; not directly readable, bot-verification gated)