Citrix Urges Admins to Patch Critical NetScaler RCE and DoS Flaw

· Original article ↗

Summary

Citrix disclosed CVE-2026-107406, a memory overflow affecting NetScaler ADC and Gateway appliances configured as SAML IdPs or SPs. It can enable remote code execution or denial of service; Citrix says it has no evidence of exploitation and urges upgrades.

Key points

  • CVE-2026-107406 is a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.
  • Only appliances configured as SAML identity providers or service providers are vulnerable.
  • Successful exploitation could allow remote code execution or cause a denial-of-service crash.
  • Citrix reports no evidence of exploitation in the wild and urges customers to upgrade to its recommended versions.
  • Shadowserver tracks more than 21,000 internet-exposed NetScaler fingerprints, but the number of vulnerable systems is unknown.
  • Citrix has disclosed other NetScaler flaws exploited this year, including zero-days used to deploy web shells and steal credentials.

Article Details

Vulnerability Types
  • Memory overflow
  • Remote code execution
  • Denial of service
Severity
Critical
Affected Versions
  • NetScaler ADC and NetScaler Gateway 14.1 versions earlier than 14.1-73.46
  • NetScaler ADC and NetScaler Gateway 13.1 versions earlier than 13.1-64.29
  • NetScaler ADC 14.1-FIPS versions earlier than 14.1-73.46 FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP versions earlier than 13.1.37.283
Exploitation Status
not_reported
Exploit Availability
unknown
Patch Status
available

CVE

People

Vendors

Products

Related Articles