Why it matters
Administrators responsible for NetScaler ADC or NetScaler Gateway should apply Citrix’s patches promptly; the vulnerability can enable remote code execution or denial of service under specific conditions.
CVE-2026-107406
- Severity
- 9.5 Critical · CVSS 4.0 · NetScaler
- Exploited
- Not in CISA’s catalog
- Published
- NetScaler ADC
Affected: before 14.1-73.46; before 13.1-64.29; before 14.1-73.46 FIPS; before 13.1.37.283 FIPS
Fixed: 14.1-73.46; 13.1-64.29; 14.1-73.46 FIPS; 13.1.37.283 FIPS
- NetScaler Gateway
Affected: before 14.1-73.46; before 13.1-64.29
Fixed: 14.1-73.46; 13.1-64.29
What we know
Confirmed by several sources
- Citrix urged administrators to patch a critical vulnerability affecting NetScaler ADC and NetScaler Gateway. — BleepingComputer, The Hacker News, SecurityWeek
- The vulnerability could lead to remote code execution or denial of service under certain conditions. — The Hacker News, SecurityWeek
- The vulnerability is tracked as CVE-2026-107406 and is a memory overflow flaw. — The Hacker News, SecurityWeek
Reported by one source
- The flaw has a severity score of 9.5. — The Register
Open questions
- It is not yet clear whether attackers are exploiting the vulnerability. — The Register
Coverage 4 publishers
SecurityWeekFirst report
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.
-
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory…
-
Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.
-
Citrix gives NetScaler admins another critical reason to patch
No word on exploitation status, but a 9.5 severity score suggests time is of the essence
Earliest report first. Articles stay on their publishers’ sites; each link opens the original.
