Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
Citrix urges immediate patching of critical NetScaler ADC/Gateway memory-overflow flaw CVE-2026-107406 (CVSS 9.5) enabling RCE; no known exploits yet.
Citrix disclosed CVE-2026-107406, a critical memory overflow (CVSS 9.5) that can lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances configured as SAML SP or SAML IdP, plus Secure Private Access Hybrid deployments using NetScaler. Fixes shipped in versions 14.1-73.46, 13.1-64.29, and FIPS variants 14.1-73.46 FIPS and 13.1-37.283. Citrix states it is not aware of unmitigated exploitation, but the disclosure follows three recently exploited NetScaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88779).
- CVSS 9.5 memory overflow enables RCE or DoS on NetScaler ADC and Gateway.
- Affects appliances configured as SAML SP/IdP and Secure Private Access Hybrid.
- Patches available in 14.1-73.46 and 13.1-64.29 builds.
- No known exploitation yet, but prior NetScaler zero-days CVE-2026-88771/88772/88779 were exploited.
Vulnerabilities mentionedAll →
- CVE-2026-1074069.5<1%Memory overflow RCE/DoS in NetScaler ADC and Gatewaypublished · Citrix NetScaler ADC and NetScaler Gateway PoC
Full article229 words · extracted from securityweek.com · click to collapse
Citrix on Thursday warned users of a critical-severity NetScaler vulnerability that requires immediate patching.
Tracked as CVE-2026-107406 (CVSS score of 9.5), the flaw is described as a memory overflow that could lead to remote code execution (RCE) or denial-of-service (DoS).
According to Citrix, the security defect impacts NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP or SAML IdP, under specific configuration conditions.
The bug also affects Secure Private Access Hybrid deployments that use NetScaler. Customers need to update these NetScaler instances as well.
Patches were included in NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (of 13.1-FIPS and 13.1-NDcPP).
“As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability,” Citrix notes, urging customers to upgrade their instances as soon as possible.
Advertisement. Scroll to continue reading.
Citrix’s fresh warning comes days after the company sounded the alarm on CVE-2026-88779, a zero-day in NetScaler leading to DoS.
A week before, two other NetScaler zero-days were patched: CVE-2026-88771 (leading to RCE), and CVE-2026-88772 (leading to RCE or DoS). They have been exploited in attacks against government, financial services, education, legal, and professional services organizations.
Related: Critical NetScaler Vulnerability Exploited in Attacks
Related: Cisco Patches a Dozen Critical Vulnerabilities
Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
Related: SonicWall and Splunk Patch Critical Vulnerabilities