Critical Citrix NetScaler RCE Vulnerability Requires Immediate Patch for Admins

www.news4hackers.com-critical-citrix-netscaler-rce-vulnerability-requires-immediate-patch-for-admins-critical-citrix-netscaler-rce-vulnerability-requires-immediate-patch-for-admins

Citrix has issued an urgent alert to IT administrators regarding a critical vulnerability impacting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

CVE-2026-107406 Vulnerability Details

The flaw, designated CVE-2026-107406, arises from a memory overflow vulnerability that could allow threat actors to achieve remote code execution (RCE) on affected devices or induce a denial-of-service condition leading to system crashes.

Risk to Specific Configurations

Devices configured as Security Assertion Markup Language (SAML) Identity Providers (IdPs) or Service Providers (SPs) are specifically at risk.

Citrix Required Upgrades

Citrix has outlined required upgrades for affected systems, including NetScaler ADC and Gateway versions 14.1-73.46 and later, 13.1-64.29 and later, along with FIPS and NDcPP variants.

Shadowserver Exposure Data

Shadowserver, an internet threat monitoring organization, has identified over 21,000 IP addresses with NetScaler fingerprints exposed online, comprising approximately 1,500 Gateway instances and nearly 20,000 ADC appliances.

Unpatched Configuration Uncertainty

However, the exact number of unpatched or honeypot configurations remains undetermined.

Ongoing Threats from Previous Vulnerabilities

While Citrix has not confirmed active exploitation of CVE-2026-107406, the company has highlighted ongoing threats from previously disclosed NetScaler vulnerabilities.

Recent Vulnerability Examples

For example, in March, two flaws (CVE-2026-3055 and CVE-2026-4368) were addressed ahead of reported exploitation. More recently, September saw updates for two actively exploited RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that enabled deployment of web shells, credential theft, and network infiltration.

Emergency Patch for Denial-of-Service Zero-Day

An emergency patch was also released earlier this month for a denial-of-service zero-day (CVE-2026-88779), which researchers later noted could also facilitate RCE.

CISA Documentation of Exploited Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has documented 27 actively exploited Citrix vulnerabilities since November 2021, including seven linked to ransomware incidents.


Blog Image

About Author

en_USEnglish