CITRIX is urging immediate patching of a critical NetScaler vulnerability tracked as CVE-2026-107406, a memory overflow that could allow remote code execution or cause a denial-of-service. The flaw affects NetScaler ADC and NetScaler Gateway appliances when configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP) under certain conditions, and it also extends to Secure Private Access Hybrid deployments that use NetScaler. Citrix notes the high severity (CVSS 9.5) and emphasises rapid remediation to prevent potential exploitation.
Patches have been released for NetScaler ADC and Gateway in versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (covering 13.1-FIPS and 13.1-NDcPP variants). Citrix states that, at the time of their advisory, no unmitigated exploits of CVE-2026-107406 are known, but they still urge customers to upgrade as soon as possible to mitigate risk.
The warning follows earlier NetScaler zero-days and exploits linked to government, financial services, education, legal, and professional services sectors, underscoring the ongoing pressure on administrators to apply updates promptly across affected deployments.