Citrix Urges Immediate Patch for Critical NetScaler Vulnerability
Citrix issued an urgent alert on Thursday regarding a critical NetScaler vulnerability necessitating immediate remediation. The flaw, designated CVE-2026-107406 with a CVSS score of 9.5, is classified as a memory overflow vulnerability capable of enabling remote code execution (RCE) or denial-of-service (DoS) attacks. The vulnerability specifically affects NetScaler ADC and NetScaler Gateway appliances configured as Security Assertion Markup Language (SAML) Service Providers (SP) or SAML Identity Providers (IdP) under particular setup conditions. Additionally, Secure Private Access Hybrid deployments utilizing NetScaler are also impacted. Affected systems must apply updates to mitigate risks. Patches are included in NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (for 13.1-FIPS and 13.1-NDcPP configurations). Citrix stated that no unmitigated exploitation of the vulnerability has been detected as of the bulletin’s release, but emphasized the urgency of upgrading affected instances. This warning follows recent alerts about other Net
