Citrix gives NetScaler admins another critical reason to patch
Citrix warns NetScaler ADC and Gateway CVE-2026-107406 can enable remote code execution, scoring CVSS 9.5.
Citrix urged customers to patch CVE-2026-107406, a CVSS 9.5 memory-buffer flaw (CWE-119) in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. Affected SAML service-provider or identity-provider configurations depend on the build, and Secure Private Access Hybrid deployments using NetScaler also need updates. Citrix has not identified this bug as exploited, unlike earlier flaws CVE-2026-88772, targeted since at least early September, and CVE-2026-88779. JPMorgan Chase's XOR Team and Maxim Suhanov were credited with the discovery.
- CVE-2026-107406 is CVSS 9.5 and can cause RCE or denial of service.
- Vulnerable SAML SP or IdP configurations vary by NetScaler build.
- Citrix has not identified this flaw as exploited.
- Prior flaws CVE-2026-88772 and CVE-2026-88779 were exploited.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5<1%Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
Full article296 words · extracted from theregister.com · click to collapse
security
No word on exploitation status, but a 9.5 severity score suggests time is of the essence
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws.
CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5.
The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration.
REG AD
Citrix's advisory lists the affected builds and required updates. Secure Private Access Hybrid deployments using NetScaler instances also need patching.
REG AD
Citrix classifies the flaw as CWE-119: improper restriction of operations within a memory buffer.
Customers must update their own deployments. Citrix says it handles the necessary updates for its managed cloud services and Adaptive Authentication.
Citrix did not say whether this vulnerability was already exploited as a zero-day before disclosure, but credited Michael Tucker, Chew Keong Tan, and Alex Bernier at JPMorgan Chase's XOR Team, along with Maxim Suhanov, for the discovery.
Google researchers said a campaign exploiting CVE-2026-88772 had been underway since at least early September, with organizations in government, finance, legal, and education across North America and Europe likely affected.
Citrix disclosed the flaw weeks later as part of a release that patched eight vulnerabilities.
Citrix disclosed another exploited flaw, CVE-2026-88779, last Friday that carries a severity score of 8.7.
Both that flaw and the newly disclosed vulnerability involve memory overflows affecting SAML configurations. The latter can also allow remote code execution, carries a higher severity score, and has not been identified by Citrix as exploited. ®