Citrix Urges Admins to Patch Critical NetScaler RCE and DoS Flaw

Summary
Citrix disclosed CVE-2026-107406, a memory overflow affecting NetScaler ADC and Gateway appliances configured as SAML IdPs or SPs. It can enable remote code execution or denial of service; Citrix says it has no evidence of exploitation and urges upgrades.
Key points
- CVE-2026-107406 is a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
- Only appliances configured as SAML identity providers or service providers are vulnerable.
- Successful exploitation could allow remote code execution or cause a denial-of-service crash.
- Citrix reports no evidence of exploitation in the wild and urges customers to upgrade to its recommended versions.
- Shadowserver tracks more than 21,000 internet-exposed NetScaler fingerprints, but the number of vulnerable systems is unknown.
- Citrix has disclosed other NetScaler flaws exploited this year, including zero-days used to deploy web shells and steal credentials.
Article Details
- Vulnerability Types
- Memory overflow
- Remote code execution
- Denial of service
- Severity
- Critical
- Affected Versions
- NetScaler ADC and NetScaler Gateway 14.1 versions earlier than 14.1-73.46
- NetScaler ADC and NetScaler Gateway 13.1 versions earlier than 13.1-64.29
- NetScaler ADC 14.1-FIPS versions earlier than 14.1-73.46 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP versions earlier than 13.1.37.283
- Exploitation Status
- not_reported
- Exploit Availability
- unknown
- Patch Status
- available
CVE
CVE-2026-107406Tracked as CVE-2026-107406, this flaw stems from a memory overflow weakness that attackers can exploit to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes.CVE-2026-3055For instance, in March, Citrix urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.CVE-2026-4368For instance, in March, Citrix urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.CVE-2026-88771in September, it released security updates for two more actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that let attackers deploy custom web shells and tunneling malware, stealCVE-2026-88772released security updates for two more actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that let attackers deploy custom web shells and tunneling malware, steal credentials, gain rootCVE-2026-88779Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution.
People
Vendors
Products
NetScaler ADCCitrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.NetScaler GatewayCitrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.