CVE-2026-107406: Citrix NetScaler SAML Memory Overflow Flaw Enables Remote Code Execution
CVE-2026-107406 (CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer))
Severity: CRITICAL (CVSS 9.5)
Status: Public Advisory CTX697180 Disclosed October 8, 2026
Affected Systems: NetScaler ADC and NetScaler Gateway versions 14.1 (prior to 14.1-73.46) and 13.1 (prior to 13.1-64.29)
Fixed In: NetScaler ADC / Gateway 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, 13.1-37.283 FIPS
On October 8, 2026, Cloud Software Group released security bulletin CTX697180 warning of a critical remote code execution vulnerability (CVE-2026-107406, CVSS 9.5) affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway appliances. The vulnerability resides in the SAML parsing logic of the NetScaler packet engine daemon (nsppe) and allows unauthenticated remote attackers to trigger memory corruption, system reboot loops, or execute arbitrary code under the privileges of the network daemon.
Vulnerability Mechanics & Root Cause
NetScaler instances supporting enterprise Single Sign-On (SSO) are frequently configured as either a SAML Identity Provider (IdP) via samlIdPProfile or as a SAML Service Provider (SP) via samlAction. In both modes, the appliance receives XML-encoded SAML tokens over HTTP POST bindings.
When unpacking SAML response payloads, the packet engine parses XML attribute assertions. In vulnerable builds, the internal buffer allocated to store unpacked base64-encoded attribute values is allocated with a static size based on the HTTP Content-Length header rather than the validated length of the decompressed XML payload:
/* Decompiled abstraction of nsppe SAML attribute parser */
int parse_saml_attributes(const char *raw_xml, int xml_len, saml_session_t *session) {
char attr_buf[4096];
xml_node_t *attr = xml_find_node(raw_xml, "saml:AttributeValue");
while (attr) {
int val_len = attr->val_len;
// FLAW: Missing bounds check on attr_buf capacity during iterative copy
if (val_len > 0) {
memcpy(attr_buf + session->offset, attr->value, val_len); // Buffer overflow
session->offset += val_len;
}
attr = xml_next_node(attr);
}
return 0;
}
By chaining multiple nested <saml:AttributeValue> elements inside a single validly structured assertion, an unauthenticated attacker can overrun attr_buf on the execution stack. This corrupts adjacent function pointers and frame registers, triggering an immediate crash of nsppe or providing control over execution flow.
Attack Surface Identification
To determine whether a NetScaler appliance is vulnerable, network administrators can inspect the running configuration using the CLI:
# Check for SAML Service Provider configurations
show samlAction
# Check for SAML Identity Provider configurations
show samlIdPProfile
# Check for virtual servers binding SAML authentication
show authentication vserver
If any active SAML action or IdP profile is bound to an active virtual server, the appliance is exposed to CVE-2026-107406.
Detection Telemetry & Diagnostic Commands
A crashed packet engine will generate an emergency core dump in /var/crash/ and log crash events to /var/log/ns.log. Administrators should search for segmentation faults in nsppe:
# Search NetScaler logs for packet engine crash events
zgrep -i "nsppe" /var/log/ns.log* | grep -E "(signal 11|segmentation fault|core dumped)"
# Check core dump directory
ls -lh /var/crash/core.nsppe.*
Remediation Strategy
- Apply Firmware Updates: Immediately upgrade NetScaler appliances to fixed release builds:
- NetScaler ADC / Gateway 14.1: Upgrade to 14.1-73.46 or later.
- NetScaler ADC / Gateway 13.1: Upgrade to 13.1-64.29 or later.
- NetScaler ADC FIPS versions: Upgrade to 14.1-73.46 FIPS or 13.1-37.283 FIPS.
- Cloud Services: Citrix Adaptive Authentication and Citrix Cloud-managed gateways have already received vendor updates and require no customer action.
- High-Availability (HA) Upgrade Protocol: In HA pair deployments, upgrade the secondary appliance first, failover traffic, verify operational stability, and subsequently upgrade the primary node to prevent enterprise downtime.