Citrix security advisory (AV26-1023)
Canada's Cyber Centre urges patches for Citrix NetScaler ADC and Gateway flaw CVE-2026-107406.
On October 9, 2026, the Canadian Centre for Cyber Security published advisory AV26-1023 for Citrix NetScaler ADC and NetScaler Gateway. It points to Citrix's bulletin for CVE-2026-107406 and lists releases before 13.1-64.29 and 14.1-73.46, plus FIPS builds before 14.1-73.46 FIPS and 13.1-37.283 FIPS and NDcPP. The centre urges administrators to review Citrix's links and apply updates as they become available. The alert does not state a CVSS score or confirm in-the-wild exploitation.
- Canadian Cyber Centre advisory AV26-1023 covers Citrix NetScaler ADC and Gateway.
- CVE-2026-107406 affects builds before 13.1-64.29 and 14.1-73.46, including FIPS.
- Administrators are urged to review Citrix links and apply updates when available.
- The bulletin does not describe impact or say exploitation is underway.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5<1%Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107406 | Memory overflow RCE/DoS in NetScaler ADC and Gateway |
Full article67 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-1023
Date: October 9, 2026
- NetScaler ADC and NetScaler Gateway
- Prior to 13.1-64.29
- Prior to 14.1-73.46
- NetScaler ADC FIPS
- Prior to 14.1-73.46 FIPS
- Prior to 13.1-37.283 FIPS & NDcPP
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-1023