Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
blog

Another Critical NetScaler Flaw, and Why You Can’t Patch Your Way Out of the Vulnerability Deluge

Published

Oct 9, 2026

Introduction

Citrix disclosed another critical NetScaler vulnerability today (October 9, 2026). CVE-2026-107406 is a memory overflow in the SAML processing stack of NetScaler ADC and NetScaler Gateway. An unauthenticated attacker can send a crafted SAML request and trigger remote code execution or a denial-of-service crash. It carries a CVSS score of 9.5 out of 10.0, a Critical severity rating.

On its own, this is a patch-now advisory. In context, it shows what the vulnerability deluge looks like in practice. This is the fifth critical NetScaler disclosure since August.

CVE-2026-107406 explained: Two tiers of NetScaler SAML exposure

The flaw is a classic CWE-119 buffer handling error, but the exposure is not uniform. It splits into two tiers based on version and configuration.

  • Tier 1: Appliances on builds that predate the September patches are vulnerable if configured as either a SAML service provider (SP) or a SAML identity provider (IdP).
  • Tier 2: Appliances on the September-patched builds (14.1-73.37 through 14.1-73.41 and 13.1-64.23 through 13.1-64.28, plus the matching FIPS ranges) are still vulnerable if configured as a SAML IdP.

The second tier matters most. Teams that emergency-patched in September for CVE-2026-88771 and CVE-2026-88772 may believe they are done. They are not. Anyone running a SAML IdP needs a second upgrade, to 14.1-73.46, 13.1-64.29, or the equivalent FIPS and NDcPP builds.

Citrix says it is not aware of any unmitigated exploits. No public proof-of-concept exists, the CVE is not in CISA’s Known Exploited Vulnerabilities (KEV) catalog, and EPSS sits at 0.02%. That is today’s picture. NetScaler’s recent history is why it should not set the pace of your response. CVE-2026-88779, a SAML flaw disclosed days ago, was exploited in the wild, hit appliances that had been patched only days earlier, and landed in KEV on October 4. Citrix has also seen 27 of its vulnerabilities added to KEV since 2021, seven of them used in ransomware attacks. Shadowserver tracks more than 21,000 internet-exposed IPs with NetScaler fingerprints.

Citrix NetScaler - Oct2026

Black Kite's Citrix NetScaler - Oct2026 FocusTag® details critical insights on the event for TPRM professionals.

Five critical Citrix NetScaler vulnerabilities since August 2026

NetScaler used to make the news about once a month at most. Here is what Black Kite has tracked since August:

Published

FocusTag

Highlights

Black Kite's Coverage

Aug 20

Citrix NetScaler - Aug2026

Potential pre-auth RCE (CVE-2026-8452)

Focus Friday August 21, 2026

Sep 24

Citrix NetScaler - Sep2026

Actively exploited auth bypass and memory overflow (CVE-2026-19489, CVE-2026-19490)

Focus Friday September 25, 2026

Sep 28

Citrix NetScaler - Sep2026 (Latest)

Actively exploited zero-day RCE and multiple critical flaws (CVE-2026-88771 through CVE-2026-88778)

Focus Friday October 2, 2026

Oct 5

Citrix PitScaler 2

Actively exploited SAML zero-day (CVE-2026-88779)

Focus Friday October 9, 2026

Oct 9

Citrix NetScaler - Oct2026

Critical SAML memory overflow (CVE-2026-107406)

This post, October 9, 2026

That is five FocusTags in about seven weeks for one product family. Each one asks the same question of every organization: which of my vendors run this, and how exposed are they?

All Citrix NetScaler FocusTag® to date on the Black Kite platform.

All Citrix NetScaler FocusTag® to date on the Black Kite platform.

Why patching can’t keep up with 78,000 CVEs

NetScaler is one product. Zoom out and the pattern is the same. About 50,000 CVEs were published last year. We are only in early October and the count is already close to 78,000. Even the best-run patching program cannot clear that volume, and the gap widens with every disclosure.

Third-party risk makes it harder. You can patch your own NetScaler appliances. You cannot patch your vendors’ appliances. Your supply chain’s remote access, SSO, and application delivery sit on customer-managed infrastructure you do not control. When a flaw like this lands, the question is not how fast you can patch. It is which of your vendors are exposed, which exposures are most likely to be weaponized, and who you call first.

We cannot patch our way out of the deluge. The way out is prioritization and rapid risk response.

Four requirements for rapid third-party vulnerability response

An effective response to a vulnerability like CVE-2026-107406 has four properties:

  1. Speed. Intelligence arrives in hours, not after a weekly scan cycle.
  2. Context. It combines severity, weaponization potential, and actual exposure, not CVSS alone.
  3. Ecosystem reach. It covers your vendors and their Nth-party dependencies, not just your own estate.
  4. Actionability. It tells you what to ask, what to verify, and what to escalate.

How Black Kite FocusTags® identify exposed vendors

FocusTags® are Black Kite’s answer to this problem. Each FocusTag bridges a global threat to your specific ecosystem. For CVE-2026-107406, the FocusTag:

  • Identifies the affected products and versions, including the Tier 1 and Tier 2 distinction
  • Weighs weaponization potential (exploitability), severity, and exposure together
  • Maps the vulnerability to the vendors in your portfolio that show affected NetScaler instances
  • Includes the configuration checks and recommended actions for security teams and vendor conversations

The difference is visible in the Tags view. Filter on “scaler” and you can see each NetScaler event, its CVEs, its publish date, and how many of your vendors showed exposure when it was published and how many still do. That turns “another NetScaler advisory” into a ranked list of vendors to contact.

The speed comes from how we build them. Automated data collection and enrichment, analysis by AI agents, and review by the Black Kite Research Group™ combine to produce relevant intelligence within hours of disclosure.

Filtered view of vendors with Citrix NetScaler FocusTags® on the Black Kite platform.

Filtered view of vendors with Citrix NetScaler FocusTags® on the Black Kite platform.

What’s next: contextualized vulnerability prioritization

FocusTags are the foundation. Next, we are adding contextualized vulnerability prioritization on top of them. It will assess four additional dimensions:

  • Automatability: how easily an attacker can exploit the flaw at scale
  • Impact: what a successful exploit gives the attacker
  • Chainability: whether the flaw can be combined with others, as NetScaler flaws often are
  • Ecosystem exposure: how widely the affected technology appears across your supply chain

The goal is to turn a flood of advisories into a short, defensible list of what to act on first.

How to respond to CVE-2026-107406: a checklist for TPRM teams

  • Identify exposed vendors. Use the Citrix NetScaler - Oct2026 FocusTag to see which vendors in your ecosystem run NetScaler.
  • Check the configuration. Look for add authentication samlAction (SAML SP) and add authentication samlIdPProfile (SAML IdP) in running configurations, and determine which tier applies.
  • Do not assume September patching is enough. Appliances on 14.1-73.37 through 14.1-73.41 or 13.1-64.23 through 13.1-64.28 configured as a SAML IdP need the October fix.
  • Treat it as an emergency cadence. Exploitation of the recent NetScaler flaws moved fast, so do not wait for KEV.
  • Engage vendors with specific questions. Ask which version they run, whether they use SAML, and when they will upgrade. The Bridge™, Black Kite’s vendor engagement platform, can streamline that outreach.
  • Restrict and monitor. Limit access to SAML endpoints to known IP ranges, and review logs and crash dumps for anomalous SAML requests or unexpected process terminations.

The deluge is not slowing down. The organizations that handle it best will not be the ones that patch the most. They will be the ones that see their exposure first and act on the right vulnerabilities first.

See which of your vendors are exposed to CVE-2026-107406. Log in to Black Kite and open the Citrix NetScaler - Oct2026 FocusTag, or request a demo.

Frequently asked questions about CVE-2026-107406

What is CVE-2026-107406?
A critical memory overflow in the SAML processing component of Citrix NetScaler ADC and Gateway that allows unauthenticated remote code execution or denial of service.

Which NetScaler versions are vulnerable?
Builds before 14.1-73.46 and 13.1-64.29 (and the corresponding FIPS releases). SAML SP and IdP configurations are vulnerable on older builds, and SAML IdP configurations are vulnerable on September-patched builds.

Is CVE-2026-107406 actively exploited?
Not at the time of publication. There is no public proof-of-concept and it is not in CISA’s KEV catalog. Recent NetScaler flaws have been exploited quickly, so patch promptly.

How can I tell if my vendors are affected?
You need visibility into the technology your vendors run and its version and configuration. A third-party cyber risk intelligence platform like Black Kite maps the vulnerability to your vendor portfolio so you can prioritize outreach.