Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

Citrix Patches Critical NetScaler SAML Flaw CVE-2026-107406: What Canadian Gateway Teams Must Check

What Happened

Citrix released fixes for CVE-2026-107406, a memory overflow with a CVSS score of 9.5. SecurityWeek reports it affects NetScaler ADC and NetScaler Gateway appliances configured as a SAML service provider or SAML identity provider. Secure Private Access Hybrid deployments built on NetScaler are also affected. A successful attack leads to remote code execution or denial of service.

Fixed builds are 14.1-73.46 and 13.1-64.29, along with FIPS and NDcPP builds listed in the Citrix bulletin. Citrix says it knows of no unmitigated exploits. The Hacker News also covers the release.

Why This Matters for Canadian Organizations

This is the fourth NetScaler memory flaw in weeks. Attackers exploited CVE-2026-88771 and CVE-2026-88772 against government, financial services, education, and legal targets. The Canadian Centre for Cyber Security updated alert AL26-024 on October 3 for those two flaws. It has not yet published an alert for this one in the pages we reviewed.

NetScaler sits at the edge of banks, hospitals, universities, and provincial networks across Canada. A SAML configuration is common for single sign-on, so many Canadian deployments match the affected profile. A compromised gateway hands an attacker a trusted position inside the network. Federally regulated institutions should log this under OSFI Guideline B-13 technology risk reviews. A breach of personal data on the appliance also carries PIPEDA reporting duties.

What to Do

Check your NetScaler configuration for SAML SP or IdP profiles. Upgrade to a fixed build as soon as your change window allows. Attackers moved on the earlier flaws within days, so do not wait for a report of exploitation here. Review the gateway for unexpected web shells, new superusers, and odd URL mappings. Restrict management interfaces to internal networks. Read our TechTalk archive for earlier NetScaler coverage.

Enjoy this article? Don’t forget to share.