Futureweb

Security

What the second October NetScaler bulletin changes

Citrix bulletin CTX697191 covers CVE-2026-107406 on SAML-configured NetScaler appliances. Fixed builds start at 14.1-73.46 and 13.1-64.29. It is not the earlier October CVE.

The short version

A newer fixed build for CVE-2026-107406, a memory overflow that can lead to remote code execution or denial of service on customer-managed NetScaler appliances configured for SAML. The fixed lines start at 14.1-73.46 and 13.1-64.29.

What happened

On October 8, 2026, Citrix published bulletin CTX697191 for CVE-2026-107406 in customer-managed NetScaler ADC and NetScaler Gateway. The bulletin calls it a memory overflow that can lead to remote code execution or denial of service. It rates the issue Critical and prints a CVSS v4 base score of 9.5. It says the appliance is in scope when configured as a SAML service provider or a SAML identity provider, with a further split by version. SecurityWeek, BleepingComputer, and The Register reported the bulletin on October 9. The page filing the bulletin, not a configuration recipe, is Futureweb.

How this differs from the earlier NetScaler bulletin

CTX697174, filed earlier on this desk, covered CVE-2026-88779, a memory overflow described there as denial of service, and it pointed customers to 14.1-73.41 and 13.1-64.28. CTX697191 is a second identifier. Its affected list includes the band from 14.1-73.37 through 14.1-73.41, and the band from 13.1-64.23 through 13.1-64.28, and it says those bands apply when the appliance is a SAML identity provider. Builds older than 14.1-73.37 and 13.1-64.23 are in scope as either a SAML service provider or a SAML identity provider. The fixed builds in the new bulletin start at 14.1-73.46 and 13.1-64.29. The earlier brief is what the NetScaler bulletin names.

Who is in scope

The bulletin applies to customer-managed appliances. It says Secure Private Access Hybrid deployments that use NetScaler instances are also affected and need the same upgrades. It says Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Citrix, not by the customer. A reader whose appliance is customer-managed and configured for SAML is the person the bulletin is addressing. A reader on a Citrix-operated cloud service is, in the bulletin's own note, outside that instruction. The desk is Security.

Why it matters on this desk

The check is a bulletin number, a CVE, a date, a precondition stated in words, and a fixed-build list. This page does not print the configuration commands the bulletin uses as examples, and it does not print the CVSS vector string. The score it is willing to repeat is the base score the bulletin prints, 9.5, and the word Critical. What a CVE identifier is, for a reader who wants the difference between an identifier and a patch, is what a CVE identifier is.

What the fixed builds are

Citrix tells affected customers to install 14.1-73.46 and later, 13.1-64.29 and later releases of 13.1, 14.1-73.46 FIPS and later, and 13.1-37.283 and later on the 13.1 FIPS and NDcPP line. The FIPS ranges follow the same pattern as the mainline ranges: a narrow band that the bulletin limits to identity-provider configurations, and older builds that it includes for either SAML role. Cloud Software Group acknowledges Joshua Foote, Michael Tucker, and Eugene Lim of the XOR team at JPMorgan Chase. A hardware brief about a packaging agreement filed the same day is unrelated and sits on Hardware.

What Citrix's own follow-up adds

A Citrix community note the same day urges customers to upgrade and says that, as of the bulletin, Citrix is not aware of any unmitigated exploit. That sentence is the community note's, not a line this page is adding. The bulletin's changelog records initial publication on October 8 and a same-day link to further context. It does not, in the text fetched here, state that an attack has been observed. The outlets on October 9 urge patching. They do not replace the version list.

What to watch next

A changelog line that says exploitation has been observed, or a CISA listing of this CVE, would change the exposure sentence. A superseding build number would replace 14.1-73.46 and 13.1-64.29. Another outlet repeating the word critical would not. The October 8 bulletin is the patch record. The October 6 bulletin remains the record for the other CVE.

What this page leaves out

It leaves out the example commands, the vector string, and any description of how an overflow would be triggered. Those details are not required to say who is affected and which build is fixed. A reader who needs the commands has the bulletin. This page's job is the difference between the two October bulletins and the precondition the new one states in words. How this desk treats an advisory as the story, rather than as a procedure, is the advisory is the story.

What stays this bulletin

What stays specific is CTX697191, CVE-2026-107406, published October 8, 2026, a Critical memory overflow on customer-managed NetScaler ADC and NetScaler Gateway configured for SAML, with fixed builds beginning at 14.1-73.46 and 13.1-64.29. It is not CVE-2026-88779. It is not a Citrix-managed cloud service. SecurityWeek and the other October 9 reports confirm the bulletin was public. They are not a second version list, and this page does not treat them as one. The narrow identity-provider band is the reason this bulletin is not a reprint of CTX697174. Builds that bulletin had just recommended sit inside the new affected window when the appliance is a SAML identity provider. Customers who stopped at 14.1-73.41 or 13.1-64.28 are, on the new bulletin's own list, not done if that role applies. That is the operational fact in the bulletin. It is not a command line.

Sources

The reports this brief is filing. Futureweb did not republish them.

  1. Citrix, CTX697191 (October 8, 2026)
  2. Citrix, customer guidance for CVE-2026-107406
  3. SecurityWeek, Citrix NetScaler patching

Questions

Which bulletin covers CVE-2026-107406?

Citrix bulletin CTX697191, first published October 8, 2026. It is a different bulletin from CTX697174, which covered CVE-2026-88779.

What does Citrix say CVE-2026-107406 can cause?

A memory overflow leading to remote code execution or denial of service, on customer-managed NetScaler ADC and NetScaler Gateway. The bulletin rates it Critical, with a CVSS v4 base score of 9.5.

When does the new NetScaler bulletin say the appliance is affected?

When it is configured as a SAML service provider or a SAML identity provider. Some version ranges in the bulletin apply only if it is a SAML identity provider.

Which fixed NetScaler builds does CTX697191 name?

14.1-73.46 and later, 13.1-64.29 and later on the 13.1 line, 14.1-73.46 FIPS and later, and 13.1-37.283 and later for the 13.1 FIPS and NDcPP line.

Does CVE-2026-107406 apply to Citrix-managed cloud services?

The bulletin says no. It applies to customer-managed NetScaler ADC and NetScaler Gateway. Citrix says it updates Citrix-managed cloud services and Adaptive Authentication itself.