Critical Citrix NetScaler RCE Vulnerability Requires Immediate Patch for Admins
Citrix has issued an urgent alert to IT administrators regarding a critical vulnerability impacting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.
CVE-2026-107406 Vulnerability Details
The flaw, designated CVE-2026-107406, arises from a memory overflow vulnerability that could allow threat actors to achieve remote code execution (RCE) on affected devices or induce a denial-of-service condition leading to system crashes.
Risk to Specific Configurations
Devices configured as Security Assertion Markup Language (SAML) Identity Providers (IdPs) or Service Providers (SPs) are specifically at risk.
Citrix Required Upgrades
Citrix has outlined required upgrades for affected systems, including NetScaler ADC and Gateway versions 14.1-73.46 and later, 13.1-64.29 and later, along with FIPS and NDcPP variants.
Shadowserver Exposure Data
Shadowserver, an internet threat monitoring organization, has identified over 21,000 IP addresses with NetScaler fingerprints exposed online, comprising approximately 1,500 Gateway instances and nearly 20,000 ADC appliances.
Unpatched Configuration Uncertainty
However, the exact number of unpatched or honeypot configurations remains undetermined.
Ongoing Threats from Previous Vulnerabilities
While Citrix has not confirmed active exploitation of CVE-2026-107406, the company has highlighted ongoing threats from previously disclosed NetScaler vulnerabilities.
Recent Vulnerability Examples
For example, in March, two flaws (CVE-2026-3055 and CVE-2026-4368) were addressed ahead of reported exploitation. More recently, September saw updates for two actively exploited RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that enabled deployment of web shells, credential theft, and network infiltration.
Emergency Patch for Denial-of-Service Zero-Day
An emergency patch was also released earlier this month for a denial-of-service zero-day (CVE-2026-88779), which researchers later noted could also facilitate RCE.
CISA Documentation of Exploited Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has documented 27 actively exploited Citrix vulnerabilities since November 2021, including seven linked to ransomware incidents.
