NetScaler patch priority: a third Citrix bulletin in two weeks fixes a critical SAML flaw
Two of the September flaws were exploited before a fix existed, and a SAML bug was used against appliances last week. One upgrade now covers all three bulletins.
Jordan Harrison / UnsplashCitrix published its third NetScaler security bulletin in under two weeks on October 8. The new flaw, CVE-2026-107406, is a memory overflow in NetScaler ADC and NetScaler Gateway appliances configured for SAML sign-in. It can lead to remote code execution or denial of service and carries a CVSS 4.0 score of 9.5.
Citrix said it was not aware of exploitation when it published bulletin CTX697191. NHS England's security operations center said on October 9 that exploitation is likely, noting that attackers have hit recent NetScaler flaws within hours of proof-of-concept code going public.
Three bulletins, one upgrade
| Bulletin | Published | CVEs | Status |
|---|---|---|---|
| CTX697096 | September 27 | CVE-2026-88771 to CVE-2026-88778 | 88771 and 88772 exploited as zero-days, both in CISA's KEV catalog |
| CTX697174 | October 3 | CVE-2026-88779 (SAML, CVSS 8.7) | Targeted attacks causing outages; added to KEV on October 4 |
| CTX697191 | October 8 | CVE-2026-107406 (SAML, CVSS 9.5) | No known exploitation at publication |
The fixed builds for CVE-2026-107406 are 14.1-73.46 and 13.1-64.29, 14.1-73.46 FIPS, and 13.1-37.283 for 13.1-FIPS and 13.1-NDcPP. These builds also carry the fixes from the two earlier bulletins, according to consultant Thomas Poppelgaard's breakdown of the advisories.
If you patched for the September or early October bulletins and your appliance acts as a SAML identity provider, you still need this upgrade. Builds 14.1-73.37 through 73.41 and 13.1-64.23 through 64.28 are affected in that role. Versions 12.1 and 13.0 are end of life and get no fix, so they need to move to 14.1.
What attackers did with the September flaws
eSentire's threat team saw CVE-2026-88771 exploited at its customers from about 24 hours after Citrix disclosed it on September 27, and found one web shell that predated disclosure. On compromised appliances, attackers:
- planted PHP web shells disguised as other files, such as a .deb package under the VPN scripts folder
- changed the Apache configuration to run them
- added a backdoor superuser to /flash/nsconfig/ns.conf
- copied the whole /flash/nsconfig directory to their own server
Finland's National Cyber Security Centre said on October 1 that it had received reports of intrusions in Finland through these flaws, and that it had found hundreds of affected appliances in the country. Its advice: patching alone is not enough, so check for signs of earlier compromise as well.
What IT teams should do
- Upgrade every NetScaler ADC and Gateway appliance to 14.1-73.46 or 13.1-64.29 (or the matching FIPS build). Treat internet-facing Gateway appliances first.
- Check SAML before you upgrade. The new builds reject unsigned SAML assertions, so confirm your identity provider signs them or sign-ins will fail.
- Turn on Enhanced ISN Generation after upgrading. CVE-2026-88778 needs the setting as well as the new firmware, and it has to be set in every admin partition.
- Run Citrix's indicator-of-compromise scan, and run it again when Citrix updates it.
- If an appliance shows signs of compromise, build a new one. Don't restore it through HA sync from the suspect node, and rotate every secret it held.
- Move any 12.1 or 13.0 appliances to 14.1.
Sources
- NHS England Digital: Critical remote code execution vulnerability in Citrix NetScaler (CC-4865)
- Poppelgaard: CVE-2026-88771 through CVE-2026-88778, CVE-2026-88779 and CVE-2026-107406, what you should know
- eSentire: Tracking Citrix NetScaler exploitation of CVE-2026-88771
- NCSC-FI: Critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, several intrusions in Finland