Do not carry the old CVE's status into this one

NetScaler teams have had several urgent advisories in a short period. Citrix's 8 October bulletin identifies CVE-2026-107406 as a separate memory-overflow issue that may lead to remote code execution or denial of service. It has its own affected-build and SAML-role conditions; installing an earlier fix should not be taken as proof that this issue is addressed.

Exploitation status matters

At publication, Citrix said it was not aware of unmitigated exploits of this vulnerability. The site's earlier article covers different NetScaler flaws that Citrix confirmed were exploited. Do not describe CVE-2026-107406 as an exploited zero-day without new evidence.

Version alone does not answer the question

Citrix says affected customer-managed NetScaler ADC and Gateway appliances must meet version-specific conditions and be configured as a SAML identity provider or service provider. For newer affected build ranges, the relevant role is the identity provider; older ranges can be affected as either role. Customer-managed NetScaler instances in Secure Private Access Hybrid deployments also require review. Citrix-managed cloud services are updated by the provider.

The vendor gives administrators configuration entries to identify the SAML role, along with the fixed build for each supported software branch. That is why a fleet-wide announcement is less useful than an appliance-by-appliance matrix. One node may be unaffected by configuration, another may need a different patch branch, and a standby node can be missed if only the active gateway is checked.

Turn the bulletin into verifiable work

  1. 1

    Inventory the fleet. List every customer-managed ADC and Gateway node, including HA peers and Secure Private Access Hybrid components.

  2. 2

    Check SAML role and build. Use Citrix's bulletin to compare each running build with the applicable SP or IdP precondition. Keep the configuration evidence with the ticket.

  3. 3

    Upgrade the right branch. Install Citrix's fixed version for that edition, following the supported change sequence. Avoid treating a build number from another branch as equivalent.

  4. 4

    Verify service and state. Confirm the running version on each node after restart and test authentication flows. Keep investigation of the earlier exploited CVEs as a separate task.

One inventory, two distinct questions

Use the same NetScaler inventory to track both the older exploited flaws and this new advisory, but do not merge their findings. For CVE-2026-107406, record the exact build, SAML role, fixed target and successful post-upgrade authentication test. For the older flaws, retain the separate compromise assessment.