Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix urges immediate patches for critical NetScaler RCE CVE-2026-107406, with no known exploitation yet.
Citrix urged immediate upgrades for CVE-2026-107406, a critical memory-overflow flaw in NetScaler ADC and NetScaler Gateway that can allow remote code execution or a denial-of-service crash. Exploitation requires the appliance to be configured as a SAML identity provider or service provider. Recommended builds include 14.1-73.46 and later and 13.1-64.29 and later, plus specified FIPS and NDcPP releases. Citrix said it is not aware of exploitation of this bug, while noting several other NetScaler flaws abused earlier in 2026; Shadowserver tracks more than 21,000 exposed NetScaler IPs.
- CVE-2026-107406 is a memory overflow enabling remote code execution or crashes.
- Only appliances configured as a SAML identity or service provider are vulnerable.
- Fixed builds include 14.1-73.46, 13.1-64.29, and listed FIPS releases.
- Citrix says it knows of no exploitation of this vulnerability.
- Shadowserver tracks over 21,000 internet-exposed NetScaler IP addresses.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5—Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
- CVE-2026-30559.34%Out-of-Bounds Read in Citrix NetScaler ADC and Gateway When Used as SAML IDP
Full article438 words · extracted from bleepingcomputer.com · click to collapse

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.
Tracked as CVE-2026-107406, this flaw stems from a memory overflow weakness that attackers can exploit to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes.
To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP).
"We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible," the company said. "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability."
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:
- NetScaler ADC and NetScaler Gateway 14.1-73.46 and later,
- NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1
- NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP
Internet threat watchdog Shadowserver tracks over 21,000 IP addresses with NetScaler fingerprints exposed on the Internet (including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances).
However, at the time, there is no information on how many are honeypots, have already been patched, or have vulnerable configurations.

While Citrix has not found evidence that attackers have begun exploiting CVE-2026-107406 in the wild, the company warned of several other NetScaler vulnerabilities that attackers have abused since the start of the year.
For instance, in March, Citrix urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.
More recently, in September, it released security updates for two more actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access, and spread into victims' internal networks.
Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.