Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
Citrix urges immediate patching of critical NetScaler ADC/Gateway memory-overflow flaw CVE-2026-107406 (CVSS 9.5) enabling RCE; no known exploits yet.
Citrix disclosed CVE-2026-107406, a critical memory overflow (CVSS 9.5) that can lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances configured as SAML SP or SAML IdP, plus Secure Private Access Hybrid deployments using NetScaler. Fixes shipped in versions 14.1-73.46, 13.1-64.29, and FIPS variants 14.1-73.46 FIPS and 13.1-37.283. Citrix states it is not aware of unmitigated exploitation, but the disclosure follows three recently exploited NetScaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88779).