Computers

Citrix Urges Immediate Patching of Critical NetScaler RCE Flaw

Citrix warned IT administrators to immediately patch CVE-2026-107406, a critical memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution.

Citrix is telling IT administrators to immediately patch a newly disclosed critical vulnerability tracked as CVE-2026-107406, which affects NetScaler ADC and NetScaler Gateway appliances, according to bleepingcomputer.com.

The flaw is a memory overflow weakness that can be exploited to achieve remote code execution or to trigger a denial-of-service condition. Appliances are only vulnerable if they are configured as a SAML Identity Provider or Service Provider, according to Citrix.

In its bulletin, Citrix said it is not aware of any unmitigated exploits of CVE-2026-107406 as of the publication date.

Patched versions and prior Citrix incidents

Citrix recommends upgrading to NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, 13.1-64.29 and later, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS/13.1-NDcPP 13.1.37.283 and later.

The advisory follows a string of NetScaler security incidents. In March, Citrix urged customers to patch two NetScaler issues (CVE-2026-3055 and CVE-2026-4368) days before attackers began abusing them, and in September the company released security updates for two actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772). Earlier in the month, Citrix issued emergency updates for a NetScaler denial-of-service zero-day (CVE-2026-88779).

Shadowserver tracks over 21,000 IP addresses with NetScaler fingerprints exposed on the Internet, including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances. CISA has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks.

Quick answers

Which NetScaler versions fix CVE-2026-107406?

Citrix recommends upgrading to NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, 13.1-64.29 and later, 14.1-FIPS 14.1-73.46 FIPS and later, and 13.1-FIPS/13.1-NDcPP 13.1.37.283 and later.

Which NetScaler configurations are vulnerable to CVE-2026-107406?

Only appliances configured as a SAML Identity Provider or Service Provider are vulnerable, according to Citrix.

Is CVE-2026-107406 being exploited in the wild?

Citrix said it is not aware of any unmitigated exploits of CVE-2026-107406 as of the bulletin's publication.

Source