Vulnerability Bulletins]TLP WHITE: Citrix Patches Critical NetScaler ADC and NetScaler Gateway Flaw (CVE-2026-107406)
On October 8, 2026, Citrix disclosed a critical memory overflow vulnerability (CVE-2026-107406) affecting NetScaler ADC and NetScaler Gateway, assigning it a CVSS score of 9.5 out of 10.0.
Additional Info
Analysis
Under specific configuration conditions, an attacker could exploit this flaw to achieve remote code execution (RCE) or trigger a denial-of-service (DoS) state. The flaw was discovered and reported by security researchers.
Vulnerability exposure strictly requires appliances to be actively configured as a SAML Identity Provider (IdP) or Service Provider (SP). While threat intelligence group Shadowserver monitors over 21,000 internet-facing NetScaler IP addresses globally, Citrix reports no known active exploitation in the wild, though NetScaler products remain frequent targets for threat actors.
To eliminate the security risk, Citrix released patched firmware versions across all supported release trains, including standard and FIPS-compliant builds. Because unmitigated vulnerabilities on perimeter devices pose severe risk to corporate networks, immediate assessment and firmware upgrades are required for all instances running SAML authentication services.
Citrix is recommending that its customers immediately apply available updates:
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
- Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP
View the detailed report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact: