Science & Tech · Cybersecurity · 2 days ago
Citrix urges immediate patching of critical NetScaler flaw
Citrix has warned customers about a critical flaw in NetScaler ADC and NetScaler Gateway systems, which organizations use for networking and secure remote access.
The flaw can allow an attacker to run code remotely or make an affected system stop working.
It affects systems configured as a SAML identity provider or service provider under specific conditions, as well as Secure Private Access Hybrid deployments that use NetScaler.
Citrix says it has no reports of unmitigated attacks exploiting this flaw.
The company has released fixed software versions and urges affected customers to upgrade as soon as possible.
The warning comes after other NetScaler flaws were exploited in attacks this year, including attacks on organizations in several sectors.
Installing the recommended updates is the next step for customers with affected systems.
Citrix urged customers to immediately patch critical vulnerability CVE-2026-107406 in NetScaler ADC and NetScaler Gateway appliances.
The memory overflow flaw could allow remote code execution or cause a denial-of-service condition.
The affected appliances must meet specific configuration conditions, including use as a SAML identity provider or service provider.
Citrix said it was not aware of any unmitigated exploits of the vulnerability when it published its bulletin.
Patches are available in specified NetScaler software versions.
- Who
- Citrix warned customers and IT administrators.
- What
- The company urged immediate patching of critical NetScaler vulnerability CVE-2026-107406.
- When
- Thursday, according to SecurityWeek; the articles were published on October 9, 2026.
- Where
- NetScaler ADC and NetScaler Gateway appliances, including Secure Private Access Hybrid deployments that use NetScaler.
- Why
- The memory overflow flaw could enable remote code execution or denial of service on affected systems.
This story does not have two clearly opposing sides.
We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible,
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability,
Citrix urged customers to patch two other NetScaler security issues, CVE-2026-3055 and CVE-2026-4368.
Citrix released updates for NetScaler zero-days CVE-2026-88771 and CVE-2026-88772, which were exploited in attacks.
Citrix issued emergency updates for NetScaler denial-of-service zero-day CVE-2026-88779.
Citrix warned users about CVE-2026-107406 and urged them to upgrade affected instances.
- Vulnerability
- CVE-2026-107406
- CVSS score
- 9.5
- Flaw type
- Memory overflow
- Affected products
- NetScaler ADC and NetScaler Gateway
- Patched versions
- 14.1-73.46; 13.1-64.29; 14.1-73.46 FIPS; 13.1.37.283 for 13.1-FIPS and 13.1-NDcPP











