Citrix urges NetScaler admins to patch critical RCE flaw

Citrix has urged NetScaler ADC and Gateway administrators to patch CVE-2026-107406, a critical remote code execution and denial-of-service vulnerability carrying a CVSS v4.0 score of 9.5.

Configuration Triggers Across NetScaler ADC and Gateway Builds

Exposure to CVE-2026-107406 depends heavily on specific appliance configurations and software versions. According to details tracked by Cyber Security News, the vulnerability affects appliances acting as Security Assertion Markup Language (SAML) identity providers or service providers. Administrators can identify these parameters by checking for add authentication samlAction for SAML service provider setups or add authentication samlIdPProfile for identity provider configurations.

Older supported NetScaler builds face broader exposure when configured as either a SAML SP or IdP. Meanwhile, more recent builds are vulnerable exclusively when operating in the SAML identity provider configuration. Secure Private Access Hybrid deployments utilizing affected NetScaler instances also require immediate administrative updates.

Patching Priority and Fixed Software Versions

Citrix published security bulletin CTX697191 on October 8, 2026, outlining the necessary updates for customer-managed appliances. Administrators must manually update their instances, whereas Citrix handles the necessary updates for its managed cloud services and Adaptive Authentication environments.

Citrix urges NetScaler admins to patch critical RCE flaw
Photo: securityweek.com

To mitigate the memory overflow vulnerability, organizations must upgrade to specific fixed builds depending on their branch. The required versions include NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1-37.283 for 13.1-FIPS and NDcPP deployments.

Recent Exploitation Waves Targeting NetScaler Infrastructure

The discovery of CVE-2026-107406 follows a punishing sequence of security disclosures for NetScaler products. Earlier in the month, Google researchers identified zero-day campaigns exploiting CVE-2026-88772 against government, finance, education, and legal entities across North America and Europe. Citrix subsequently disclosed another exploited memory overflow flaw, CVE-2026-88779, carrying an 8.7 severity score. While Citrix stated that it was not aware of unmitigated exploits for CVE-2026-107406 at the time of its bulletin publication, the continuous cadence of SAML-related memory vulnerabilities underscores an urgent operational priority for enterprise IT teams managing perimeter infrastructure.

Citrix NetScaler Critical Flaws Exploited for Weeks

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Mike Tierney releases NFL Week 5 parlay picks for favorites and underdogs