P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Citrix's third NetScaler bulletin in 11 days lists the previous fix build as affected, for SAML identity providers

Citrix's 8 October bulletin for CVE-2026-107406 (9.5) says an appliance on 14.1-73.41 or 13.1-64.28, the builds that fixed the last flaw, is affected if it is a SAML identity provider. Citrix says it is not aware of any unmitigated exploits, which is narrower than none.

By Parminder Kumar Sharma · · 21 min read

A dark equipment room: a black rack holds three identical graphite network appliances, each with one amber light, and below them a graphite laptop on a steel cart shows a blank sign-in screen of rounded empty fields. Text on the left reads: The previous NetScaler fix build is affected, for SAML IdPs. 3 in 11 days: NetScaler bulletins on 27 Sep, 3 Oct and 8 Oct.

Three bulletins in 11 days, and the newest reaches back to the previous fix build

Citrix published its third NetScaler ADC and Gateway security bulletin in 11 days (derived from the changelog dates) on Thursday 8 October 2026: CTX697191 for CVE-2026-107406, a memory overflow that Citrix scores 9.5 (CVSS 4.0, Critical) and says could lead to remote code execution or denial of service. The others came on 27 September (CTX697096, eight CVEs) and 3 October (CTX697174, one CVE), so the three carry ten CVEs (derived). The checkable part is in the version ranges. The 3 October bulletin named 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS and 13.1-37.282 as the builds that fix CVE-2026-88779. The 8 October bulletin lists those same four builds as the newest it counts as affected, for an appliance configured as a SAML identity provider. An appliance that took the 3 October fix build, as Citrix asked, is inside the new range if it is a SAML IdP. CISA's federal due date for the 3 October flaw, 7 October, fell one day before the new bulletin.

What that does not establish. It does not say CVE-2026-107406 is being exploited: the bulletin is silent, and the one statement, in a Citrix blog, is that Citrix was not aware of any unmitigated exploits when the bulletin was published. It does not say how many appliances meet the condition, because Citrix prints no share of NetScalers that are SAML service providers or identity providers. It does not say the flaw can be reached without an account in practice: the vector rates privileges required as none, but Citrix's text does not use the word unauthenticated here. And it does not say the three bulletins describe one cause. This briefing stays at defender level: no trigger details, no requests, no indicators. Citrix publishes none.

Earlier briefings cover what came before: 22 days of exploitation before the 27 September patch, the eight-flaw bulletin and its three-day clock, LevelBlue's fourth web shell disguise and the third exploited flaw, CVE-2026-88779. This one covers what the third bulletin adds, and a question the others left open: what an appliance already patched twice should do now.

What the bulletin states, and what it leaves out

Citrix's bulletin and blog are the primary sources, read in full. Citrix, part of Cloud Software Group, sells the appliances, writes the severity label and scores the flaw as the CVE numbering authority, so this is its own account of its own product. Wording in quotation marks is Citrix's.

What Citrix states about CVE-2026-107406 in bulletin CTX697191 and its blog, and what it does not. Read on 9 October 2026.

QuestionStatedNot stated
What is the flaw?"Memory overflow vulnerability leading to Remote Code Execution or Denial of Service". CWE-119. Critical, CVSS 4.0 base 9.5 assigned by Citrix: network, high attack complexity, no privileges, no user interaction, high impact all round.The component, the SAML message or endpoint involved, or whether code execution or denial of service is the realistic outcome.
Does it need an account?The vector reads privileges required none. The text does not say "unauthenticated" here. It does for CVE-2026-88771.What an attacker must be able to reach, or whether SAML endpoints must face the internet.
Who is affected?Customer-managed ADC and Gateway "configured as a SAML SP or SAML IdP, subject to the following version-specific requirements", and Secure Private Access Hybrid deployments using NetScaler.How many deployments are SAML SP or IdP. Whether the 15.1 Technology Preview, 12.1 or 13.0 are affected.
Is there a mitigation?None. No workaround section in the bulletin; the blog names none.Any signature, setting or interim step. The 3 October Global Deny List signatures are for CVE-2026-88779.
Is it exploited?Bulletin: nothing. Blog: "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability." CISA catalogue 2026.10.08: not listed.That there is none. Any time after publication. What "unmitigated" leaves out. A CISA reading: none is on the CVE.org record.
Any indicators?None. The blog points to the Secure Deployment Guide and the NetScaler Console security advisory.An indicator, log pattern or detection.
Who found it?The bulletin thanks four people, the same four as on the 27 September bulletin. This briefing names none.What each reported, or whether anyone has published details.

The other records. CVE.org's record (published 21:18 UTC on 8 October) has Citrix's description and score, no weakness class and no credits. Its structured version data lists everything below the fixed build as affected and has no field for the IdP-only split, which is only in the description text: our reading is that a scanner fed from that data alone would report more appliances than the bulletin does. NVD's record (22:17 UTC) shows Received, Citrix's score only, no weakness class and no configuration data. The CVE ID was reserved at 00:18 UTC on 8 October, about 21 hours before publication (derived); a reservation is bookkeeping, not a discovery date.

The condition is SAML, and Citrix gives no share

Nine of the ten CVEs in the three bulletins name a configuration condition in Citrix's own table (derived). The exception is CVE-2026-88771, which affects the default configuration. A named condition tells a reader what to look for, not how common it is, and for SAML Citrix says nothing on that. What the bulletin gives is the check: the saved configuration holds an entry for a SAML authentication action (a service provider) or for a SAML identity provider profile. Both entries are printed in the bulletin's section on steps to determine whether an appliance meets the preconditions; they are there, not here. A build number cannot answer the question, and this bulletin makes the answer depend on both.

Where five Citrix NetScaler bulletins, 30 June to 8 October 2026, name SAML in a precondition, read from Citrix's pages. Other 2026 bulletins were not read, so this is not a count of everything Citrix published.

Bulletin and dateCVEsWhere it names SAML
CTX696604, 30 June6CVE-2026-8451 only: "must be configured as a SAML IDP". CVE-2026-8452 names a Gateway or AAA virtual server.
CTX696939, 19 August2CVE-2026-19490: from some builds, "configured with a SAML action" on a Gateway or AAA virtual server.
CTX697096, 27 September8None. The blog says the update stops supporting a setting that turned off signed-assertion checks, and links it to no CVE.
CTX697174, 3 October1CVE-2026-88779: SAML SP or IdP.
CTX697191, 8 October1CVE-2026-107406: SAML SP or IdP; IdP only on the newest affected builds.

Four of the 18 CVEs in those bulletins name SAML (derived), and both in the last two do. That supports a practical point: the SAML role is the configuration to inventory before the next bulletin. It does not support a claim that the flaws share a cause.

Does the exploited pair share anything with this flaw?

The two flaws Citrix says were exploited on 27 September, CVE-2026-88771 and CVE-2026-88772, are the subject of the 22 days briefing. Set beside the two later flaws, in Citrix's own words, the overlap is narrow.

Citrix's title, weakness class, condition and vector for four NetScaler flaws, from bulletins CTX697096, CTX697174 and CTX697191. Status is as Citrix and CISA state it.

CVE and statusCitrix title and classCondition and vector
88771. Exploits observed (Citrix). CISA catalogue."improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands". CWE-20.None: default configuration. Complexity low. 9.5.
88772. Exploits observed (Citrix). CISA catalogue."Memory overflow vulnerability leading to Remote Code Execution or Denial of Service". CWE-119.DTLS, on by default on VPN virtual servers. Complexity high. 9.5.
88779. Blog: attacks observed. CISA catalogue."Memory overflow vulnerability leading to Denial of Service". CWE-119.SAML SP or IdP. Complexity low, availability impact only. 8.7.
107406. Blog: not aware of unmitigated exploits. Not in catalogue."Memory overflow vulnerability leading to Remote Code Execution or Denial of Service". CWE-119.SAML SP or IdP; IdP only on the newest affected builds. Complexity high. 9.5.

Stated. Three of the four are CWE-119 memory overflows. CVE-2026-107406's title is word for word CVE-2026-88772's, and its vector differs in one of the eleven base metrics: the effect on systems beyond the appliance is Low here and High there. It shares the SAML condition with CVE-2026-88779. Not stated. That any two share code, a component or a root cause. Mandiant's post on CVE-2026-88772 ties that flaw to DTLS and does not contain the word SAML; we searched it this morning. A shared class describes the kind of mistake, not where it was made.

Fixed builds per branch, and the band in between

Citrix prints one shape for all four build lines. Below the build that fixed the 27 September flaws, a SAML service provider or identity provider is affected. From that build to the one that fixed the 3 October flaw, inclusive, only an identity provider is. The fix is the build above that band, written "and later releases". Citrix's flow chart on its blog says the same: a service provider in the middle band needs no action "for this CVE", while a non-SAML appliance below the band is told the CVE does not apply but to upgrade anyway.

Affected bands and first fixed builds for CVE-2026-107406 as Citrix prints them in CTX697191. Citrix writes the 13.1 FIPS and NDcPP builds with a dash in the affected ranges and dots in the fixed build.

Build lineAffectedFirst fixed
14.1 ADC and GatewayBefore 14.1-73.37: SP or IdP. 14.1-73.37 to 14.1-73.41: IdP only.14.1-73.46 and later
14.1 FIPS ADCBefore 14.1-73.37 FIPS: SP or IdP. 14.1-73.37 FIPS to 14.1-73.41 FIPS: IdP only.14.1-73.46 FIPS and later
13.1 ADC and GatewayBefore 13.1-64.23: SP or IdP. 13.1-64.23 to 13.1-64.28: IdP only.13.1-64.29 and later releases of 13.1
13.1 FIPS and NDcPP ADCBefore 13.1-NDcPP 13.1-37.279: SP or IdP. 13.1-37.279 to 13.1-37.282: IdP only.13.1.37.283 and later
Time axis to scale of three Citrix NetScaler bulletins in 11 days: 27 September, 3 October and 8 October, with Citrix's exploitation statement for each. Below it, four cards, one per build line, each with three bands: before the 27 September fix build, SAML SP or IdP affected; up to the 3 October fix build, SAML IdP only; then the 8 October fix build. 14.1 builds 73.42 to 73.45 are not stated.
Drawn from Citrix bulletins CTX697096, CTX697174 and CTX697191 and the Citrix blogs for the last two, read on 9 October 2026. The time axis is to scale. Build numbers are as Citrix prints them.

Splunk's and SonicWall's advisories of the same week had the same shape, a fix build named as the newest affected one: Splunk and SonicWall. Here the gap is five days, not 49 or 35.

Two gaps. On 14.1 the bands end at 14.1-73.41 and the fix starts at 14.1-73.46. The bulletin does not say what 14.1-73.42 to 14.1-73.45 are; the safe reading is to move to 14.1-73.46 or later. And the 15.1 Technology Preview, which Citrix's 27 September blog said was vulnerable to those flaws with a fix coming "shortly", appears in neither 8 October page.

Where SecurityWeek and the bulletin differ. SecurityWeek gives the same four fixed builds. It says appliances must be SAML SP or IdP "under specific configuration conditions" and does not print the IdP-only split, which separates an appliance that needs action from one that does not. Its "not aware" quotation comes from the blog; the bulletin has no exploitation statement. Its list of sectors hit by the two earlier zero-days is Mandiant's, not Citrix's, and omits technology from Mandiant's list.

Branches with no fix. The bulletin covers "supported versions" only. Citrix's legacy lifecycle table puts 13.0 out of life since 15 July 2024 and 12.1 since 30 May 2023 (12.1 FIPS ended 31 December 2025). The bulletin neither says they are affected nor names a fix. Our reading, which is inference: outside the bulletin is not outside the risk. The supported lines are not all comfortable. Citrix's product matrix, last updated 26 February 2025, lists 13.1 firmware with end of maintenance on 15 September 2026, 24 days ago (derived), and end of life on 15 September 2027. Citrix's definitions say end of maintenance means "no further code-level maintenance"; yet a bulletin dated 8 October names 13.1-64.29, 23 days after that date (derived), and nothing says how long 13.1 fixes continue. 14.1 reaches end of maintenance on 8 August 2029. Whether a 13.1 appliance counts as supported under Cyber Essentials is for the organisation and its certification body. Briefing 241 asked the same of Atlassian.

What "not aware of any unmitigated exploits" does and does not say

Citrix's sentence is narrower than "no exploitation" in four ways. It is time-limited: "as of the publication of the bulletin", 8 October. It reports Citrix's awareness, not a finding about the world. It sits in a blog, while the bulletin says nothing either way. And it carries the word "unmitigated", which Citrix used on 27 September the other way round: "Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed." There it meant deployments without the fix. Here no mitigation is named, so the word cannot narrow the sentence by a published one. Our reading, which is inference: it is the vendor's habitual qualifier, and its effect, if any, is to leave open exploitation against a deployment that has a mitigation Citrix has not named.

How the last one arrived. For CVE-2026-88779 the 3 October bulletin was silent on exploitation, the blog said Citrix "has observed targeted attacks on unmitigated NetScaler deployments", and CISA listed the flaw on 4 October, due 7 October. Both earlier exploited sets were on the catalogue within a day of the bulletin. For CVE-2026-107406 the catalogue read this morning cannot say, because it predates the CVE record. CISA has listed five NetScaler CVEs on four dates in 39 days, 26 August to 4 October, after one in March (derived from the catalogue). That predicts nothing for this CVE. It is the reason to ask again before the change closes, and to write down the time.

Three things have changed since the earlier briefings were written. The catalogue record for CVE-2026-88779 now carries forensic triage "No", where the briefing on it recorded "Yes" at about 21:00 BST on 4 October; the feed does not date the change, and CVE-2026-88771 and CVE-2026-88772 still say "Yes". NVD now shows CVE-2026-88779 as Analyzed with a CVSS 3.1 score of 7.5, where that briefing found none. And NHS England Digital's CC-4862 of 5 October says its National CSOC "assesses continued exploitation as highly likely" for CVE-2026-88779. None changes what to do about CVE-2026-107406. They are the reason to date every status.

What this means for UK organisations that run NetScaler

What can be sourced. We found no count of UK NetScaler appliances or of SAML ones, and make no claim about how widely the product is used in the public sector or in enterprise. What the record shows is that both national bodies have treated it as a product UK organisations run. The NCSC's alert of 28 September covers CVE-2026-88771 to CVE-2026-88778 and says it was "working to understand the impact" on UK organisations. NHS England Digital issued CC-4858 (28 September, High) for the two zero-days and CC-4862 (5 October, Medium) for CVE-2026-88779. As read at about 09:15 BST and again at 09:41, neither has anything on CVE-2026-107406: the NCSC's news feed has no NetScaler item after 28 September, and NHS England Digital's latest alert is CC-4863 of 8 October, on SonicWall. The NCSC alert does not mention CVE-2026-88779. Absence from those pages says nothing about what either body knows.

Patching clocks for a NetScaler update released on 8 October 2026. Sources: NCSC vulnerability management guidance v2.1 (update by default, reviewed 1 May 2026; responding to active exploitation, 1 May 2026) and Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026). Dates derived from the bulletin date.

RuleWhat it requiresDate for 8 October
NCSC update by default, internet-facingTest first, roll out, complete within 5 days. Applies to all updates regardless of severity.Tuesday 13 October. The same rule ended on 2 October for the 27 September builds and 8 October for the 3 October ones.
NCSC update by default, internal14 days.22 October
Cyber Essentials v3.3Update within 14 days of release where the vendor calls fixed flaws critical or high, or CVSS v3 is 7 or above. Software must be licensed and supported.22 October at the latest. Citrix labels this Critical. The 27 September and 3 October updates reach 11 and 17 October.
NCSC responding to active exploitationUnder 24, 48 or 72 hours plus an incident response investigation, for flaws on the CISA catalogue.Does not apply as written: not listed. If CISA lists it, whether the flaw is automatable and gives total control picks the row.

The clocks run from release of the update, so the bulletin date is a proxy: check the date on each download. An appliance that has not yet taken even the 27 September builds faces the earliest Cyber Essentials date, 11 October, a Sunday; one move to 14.1-73.46 or 13.1-64.29 or later covers all three bulletins (our reading of Citrix's rule that a later release in the same branch is acceptable). The NCSC's update guidance says that where an internet-facing service is under active exploitation you should check for compromise before applying any update, "even if the exposure was brief". No exploitation is stated for this CVE, but it is for the three before it. Cyber Essentials v3.3 also asks for unsupported software to be removed, which is the 13.1 question above.

Three bulletins in 11 days fits a pattern the NCSC has named. Its guidance on responding to active exploitation says a product that has seen a wave of attacks is more likely to have further flaws found and mass-exploited, "a process known as 'vulnerability swarming'", and that you should be ready to deploy more vendor updates in the following days: "This shouldn't stop you rolling out the first update." It lists VPNs, file transfer and remote access products among the categories more often hit, and says unnecessary functionality should be disabled or blocked. Whether SAML is that for your appliances is your decision. The NCSC's alert of 27 August, written about operational technology, tells other organisations to keep an accurate inventory of internet-facing systems, understand the function and data flows of edge devices, apply vendor updates promptly, retire end-of-life equipment and monitor for unexpected configuration changes or outbound connections.

Patched is still not clean. Citrix's blog for the 27 September flaws says an update "does not remove potential compromise artifacts or prove that exploitation did not occur before the update". That applies to an appliance moved to 73.46 today as much as to one moved to 73.37; the assessment questions are in the 22 days briefing and the LevelBlue briefing. One consequence is specific to this bulletin, and is our inference, not Citrix's: an appliance acting as a SAML identity provider signs assertions with a key that every service trusting it also trusts, so if it is ever judged compromised, rotating that key belongs in the recovery plan.

What to do, in order

Take this with you

Defender actions, in the order worth doing

  • List every NetScaler ADC and Gateway with its exact build and whether its saved configuration holds a SAML authentication action or a SAML identity provider profile. Include VPX, FIPS and NDcPP builds, both nodes of every high availability pair, and any NetScaler behind Secure Private Access Hybrid. Read the configuration, not the version, and file the no-SAML answer too.
  • Place each appliance in Citrix's bands. Below 14.1-73.37, 13.1-64.23 or the FIPS equivalents, a SAML service provider or identity provider is in scope. From there to 14.1-73.41, 13.1-64.28 or 13.1-37.282, only an identity provider is.
  • Do not read no action for this CVE as no action. A service provider on 14.1-73.37 to 14.1-73.40, or 13.1-64.23 to 13.1-64.27, is still inside the range of CVE-2026-88779, which runs to just below 14.1-73.41 and 13.1-64.28 and is on CISA's list.
  • Before you change an appliance that was reachable from the internet and has had no compromise assessment, preserve evidence: logs already forwarded off the box, a support bundle and, for a virtual appliance, a snapshot. Citrix says an update does not remove what was planted, and the NCSC says to check for compromise before updating where exploitation is active.
  • Upgrade to 14.1-73.46, 14.1-73.46 FIPS, 13.1-64.29 or 13.1.37.283, or a later release in the same branch. Read the release notes for the build you choose, which we did not. If CVE-2026-88778 applied, its separate TCP setting from the 27 September bulletin is still needed.
  • Plan the restart. The NCSC notes that isolating and replacing a system may cause a service outage. A SAML identity provider is a sign-in dependency for other services, so list what relies on it, decide the node order for a high availability pair, upgrade both nodes and do not leave a standby on an older build.
  • If you cannot upgrade today, Citrix names no mitigation for this CVE. The NCSC's general options for a service under attack are to restrict access upstream, for example to your own address ranges, or to disable the component; for SAML that means the sign-in of whatever relies on it. Decide that cost in advance, and do not assume the 3 October Global Deny List signatures cover this flaw: Citrix does not say so.
  • For appliances upgraded after 27 September or 3 October, run the compromise assessment set out in the earlier briefings, because an update is not a cleanup. Compare accounts, web server configuration and web directories with a baseline from before September, and check outbound connections against an allow-list. If an identity provider appliance is judged compromised, treat its assertion signing key as exposed (our inference).
  • Forward the appliance's audit, system and web logs to a system it cannot alter; Citrix recommends an external SIEM. Keep management addresses off the internet: the NCSC's 27 August alert says boundary devices should be managed only from a segregated management network not connected to the internet.
  • Before the change closes, re-read Citrix's bulletin and blog, CISA's catalogue, and the NCSC and NHS England Digital lists for CVE-2026-107406, and write down the time. If CISA lists it, the NCSC's compressed timelines apply and the clock restarts.
  • Ask your supplier or managed service provider in writing which appliances are SAML SPs or IdPs, which build each was on, when each was upgraded for each of the three bulletins, and who watches for the next. The NCSC says critical suppliers should be contractually liable to mitigate exploited flaws rapidly.
  • If you are in the UK and think an appliance was compromised, report it to the NCSC; NHS organisations can use the reporting route on NHS England Digital's alert pages. The NCSC's Early Warning service is free.

What is not established, and what we could not read

  • Whether CVE-2026-107406 is exploited. Citrix's bulletin is silent, its blog says it was not aware of unmitigated exploits on 8 October, and the catalogue read here predates the CVE record. We did not look for public proof-of-concept code and make no claim about any.
  • How many NetScalers are SAML SPs or IdPs, or exposed. No source we read prints a count for this CVE: Shadowserver's dashboard returned only a total chart. The 50,277 exposed instances in the 22 days briefing counted reachable NetScalers on 27 September, not SAML ones.
  • The component, the trigger and the realistic outcome. Citrix states none and this briefing gives none.
  • Why the service provider role stops being affected from the 27 September builds, what builds 14.1-73.42 to 14.1-73.45 are, and whether 12.1, 13.0 and the 15.1 Technology Preview are affected.
  • Whether the 3 October Global Deny List signatures help here. Citrix does not say.
  • The release notes and release dates of the 8 October builds. We read neither.
  • The flow chart on Citrix's blog is an image; we read it as an image and its bands match the bulletin's text.
  • The time zone of the 8 October entry. Citrix's changelog gives dates only, with the 3 October entry in Pacific time, so the 5 days between the last two bulletins is counted from changelog dates; CVE.org's publication times are 4 days 19 hours apart (derived).
  • Other 2026 NetScaler bulletins beyond the five in the SAML table. We did not read them.
  • SecurityWeek and heise are pointers only. We took no fact from either that is not on a Citrix page, and did not rely on any third-party statement that no workaround exists.

The question this leaves

Citrix has now asked customers three times in 11 days to move to a newer build, and the last notice says the build it asked for on 3 October is affected again if the appliance plays one SAML role. That can only be applied by someone who knows which role each appliance plays. A build number does not hold that, and neither does a patch ticket marked done.

So the question for your own process: which of your NetScalers is a SAML identity provider, and would your inventory tell you that, or only the build number?

Key facts

Sources

  1. PrimarySecurity bulletin CTX697191 for CVE-2026-107406, changelog 8 October 2026, read in full as served (server-rendered copy) and in a browser: description, SAML condition and version bands, CWE-119, CVSS 4.0 vector, fixed builds, acknowledgement. No exploitation or mitigation text.Citrix, Cloud Software Groupaccessed 2026-10-09
  2. PrimaryNetScaler blog on CVE-2026-107406, marked last updated 8 October 2026, 5 PM Pacific Daylight Time: the 'not aware of any unmitigated exploits' sentence and the flow chart (read as an image). Citrix wrote the labels and sells the product.Citrix, Cloud Software Groupaccessed 2026-10-09
  3. PrimarySecurity bulletin CTX697174 for CVE-2026-88779, changelog 3 October 2026 (Pacific): SAML condition, affected and fixed builds 14.1-73.41, 13.1-64.28, 13.1-37.282, CVSS 4.0 vector; no exploitation text.Citrix, Cloud Software Groupaccessed 2026-10-09
  4. PrimaryNetScaler blog on CVE-2026-88779, last updated 3 October 2026 (Pacific): 'has observed targeted attacks on unmitigated NetScaler deployments', the Global Deny List range, the 'upgrade again' instruction.Citrix, Cloud Software Groupaccessed 2026-10-09
  5. PrimarySecurity bulletin CTX697096 for CVE-2026-88771 to CVE-2026-88778, changelog 27 September 2026: titles, preconditions, vectors, fixed builds, the statement that exploits of 88771 and 88772 have been observed.Citrix, Cloud Software Groupaccessed 2026-10-09
  6. PrimaryNetScaler blog on the 27 September bulletin, last updated 30 September 2026: 'an update does not remove potential compromise artifacts', the signed-assertion change, the 15.1 Technology Preview note, the log-forwarding advice.Citrix, Cloud Software Groupaccessed 2026-10-09
  7. PrimarySecurity bulletin CTX696939 for CVE-2026-19489 and CVE-2026-19490, change log 19 August 2026: read for where it names a SAML action.Citrix, Cloud Software Groupaccessed 2026-10-09
  8. PrimarySecurity bulletin CTX696604 for six NetScaler CVEs, changelog 30 June 2026: read for where it names a SAML IdP and for the title and condition of CVE-2026-8452.Citrix, Cloud Software Groupaccessed 2026-10-09
  9. PrimaryKEV JSON feed, catalogue version 2026.10.08 released 20:09 UTC on 8 October with 1,739 entries: CVE-2026-107406 absent; the records for CVE-2026-88771, 88772 and 88779 (dates, due dates, forensic triage) and the six NetScaler entries of 2026.Cybersecurity and Infrastructure Security Agencyaccessed 2026-10-09
  10. PrimaryCVE record read as JSON from the CVE Services API: reserved 00:18 UTC and published 21:18 UTC on 8 October, Citrix's description, version data and 4.0 vector, no weakness class, no credits, no CISA data. The records for CVE-2026-88771, 88772 and 88779 read the same way.CVE Programaccessed 2026-10-09
  11. PrimaryNVD record read through the API: status Received, published 22:17 UTC on 8 October, Citrix's score only. The records for CVE-2026-88771, 88772 and 88779 read the same way for their 3.1 scores.National Vulnerability Databaseaccessed 2026-10-09
  12. PrimaryVulnerability management guidance, update by default, version 2.1, reviewed 1 May 2026: 5 days for internet-facing services, 14 days internal, the priority actions, and check for compromise before updating where exploitation is active.National Cyber Security Centreaccessed 2026-10-09
  13. PrimaryVulnerability management guidance, responding to active exploitation, version 2.1, 1 May 2026: the compressed timeline table for catalogue-listed flaws, vulnerability swarming, supplier contracts.National Cyber Security Centreaccessed 2026-10-09
  14. PrimaryNCSC alert of 28 September 2026 on CVE-2026-88771 to CVE-2026-88778: priority actions and the statement that it is working to understand the UK impact; no mention of CVE-2026-88779 or CVE-2026-107406.National Cyber Security Centreaccessed 2026-10-09
  15. PrimaryNCSC alert of 27 August 2026 on internet-exposed systems and edge devices: inventory, vendor updates, retire end-of-life equipment, management network separation, Early Warning.National Cyber Security Centreaccessed 2026-10-09
  16. PrimaryNCSC news list, 320 items, read at about 09:15 BST on 9 October: the most recent NetScaler item is 28 September.National Cyber Security Centreaccessed 2026-10-09
  17. PrimaryCyber alerts list, read at about 09:15 BST on 9 October: CC-4863 of 8 October is the latest, CC-4862 of 5 October covers CVE-2026-88779, CC-4858 of 28 September covers the two zero-days, nothing on CVE-2026-107406. CC-4862 read in full.NHS England Digitalaccessed 2026-10-09
  18. PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026, security update management: 14 days of release for critical or high updates, licensed and supported software, removal of unsupported software.National Cyber Security Centreaccessed 2026-10-09
  19. PrimaryProduct matrix, marked last updated 26 February 2025: NetScaler ADC and Gateway firmware 14.1 end of maintenance 8 August 2029 and 13.1 end of maintenance 15 September 2026, end of life 15 September 2027.Citrixaccessed 2026-10-09
  20. PrimaryLegacy product matrix, marked last updated 15 April 2024: NetScaler ADC and Gateway firmware 13.0 and 12.1 end-of-life dates.Citrixaccessed 2026-10-09
  21. PrimaryProduct lifecycle support policy: Citrix's definitions of end of maintenance and end of life.Citrixaccessed 2026-10-09
  22. PrimaryPost of 29 September 2026 on CVE-2026-88772, read for its sector list and to confirm it does not mention SAML. No technical detail is reproduced.Google Cloud, Mandiant and Google Threat Intelligence Groupaccessed 2026-10-09
  23. Reported byReport of 9 October 2026 on CVE-2026-107406, the pointer to Citrix's bulletin: fixed builds, the 'not aware' sentence and the earlier flaws. Where it differs from Citrix's pages, this briefing follows Citrix.SecurityWeekaccessed 2026-10-09
  24. Reported byReport of 9 October 2026, read as a second pointer: it carries the IdP-only split. No fact taken from it that is not on a Citrix page.heise onlineaccessed 2026-10-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.