What changed
Do not carry the old CVE's status into this one
NetScaler teams have had several urgent advisories in a short period. Citrix's 8 October bulletin identifies CVE-2026-107406 as a separate memory-overflow issue that may lead to remote code execution or denial of service. It has its own affected-build and SAML-role conditions; installing an earlier fix should not be taken as proof that this issue is addressed.
Exploitation status matters
Who is affected
Version alone does not answer the question
Citrix says affected customer-managed NetScaler ADC and Gateway appliances must meet version-specific conditions and be configured as a SAML identity provider or service provider. For newer affected build ranges, the relevant role is the identity provider; older ranges can be affected as either role. Customer-managed NetScaler instances in Secure Private Access Hybrid deployments also require review. Citrix-managed cloud services are updated by the provider.
The vendor gives administrators configuration entries to identify the SAML role, along with the fixed build for each supported software branch. That is why a fleet-wide announcement is less useful than an appliance-by-appliance matrix. One node may be unaffected by configuration, another may need a different patch branch, and a standby node can be missed if only the active gateway is checked.
Defender workflow
Turn the bulletin into verifiable work
- 1
Inventory the fleet. List every customer-managed ADC and Gateway node, including HA peers and Secure Private Access Hybrid components.
- 2
Check SAML role and build. Use Citrix's bulletin to compare each running build with the applicable SP or IdP precondition. Keep the configuration evidence with the ticket.
- 3
Upgrade the right branch. Install Citrix's fixed version for that edition, following the supported change sequence. Avoid treating a build number from another branch as equivalent.
- 4
Verify service and state. Confirm the running version on each node after restart and test authentication flows. Keep investigation of the earlier exploited CVEs as a separate task.
Defender note
One inventory, two distinct questions
Use the same NetScaler inventory to track both the older exploited flaws and this new advisory, but do not merge their findings. For CVE-2026-107406, record the exact build, SAML role, fixed target and successful post-upgrade authentication test. For the older flaws, retain the separate compromise assessment.