www.securityweek.com 9 Oct 2026, 06:53 UTC

Citrix urges urgent patching of critical NetScaler flaw that risks remote code execution

Citrix urges urgent patching of critical NetScaler flaw that risks remote code execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CITRIX is urging immediate patching of a critical NetScaler vulnerability tracked as CVE-2026-107406, a memory overflow that could allow remote code execution or cause a denial-of-service. The flaw affects NetScaler ADC and NetScaler Gateway appliances when configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP) under certain conditions, and it also extends to Secure Private Access Hybrid deployments that use NetScaler. Citrix notes the high severity (CVSS 9.5) and emphasises rapid remediation to prevent potential exploitation.

Patches have been released for NetScaler ADC and Gateway in versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (covering 13.1-FIPS and 13.1-NDcPP variants). Citrix states that, at the time of their advisory, no unmitigated exploits of CVE-2026-107406 are known, but they still urge customers to upgrade as soon as possible to mitigate risk.

The warning follows earlier NetScaler zero-days and exploits linked to government, financial services, education, legal, and professional services sectors, underscoring the ongoing pressure on administrators to apply updates promptly across affected deployments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline