DevelopingSecurity

Citrix urges immediate patching for critical NetScaler vulnerability

Brievox summary

Citrix is urging administrators to patch a critical vulnerability affecting NetScaler ADC and NetScaler Gateway. The flaw could allow remote code execution or denial of service under specific conditions; exploitation status is not yet clear.

Image: BleepingComputer

Why it matters

Administrators responsible for NetScaler ADC or NetScaler Gateway should apply Citrix’s patches promptly; the vulnerability can enable remote code execution or denial of service under specific conditions.

CVE-2026-107406

Severity
9.5 Critical · CVSS 4.0 · NetScaler
Exploited
Not in CISA’s catalog
Published
NetScaler ADC

Affected: before 14.1-73.46; before 13.1-64.29; before 14.1-73.46 FIPS; before 13.1.37.283 FIPS

Fixed: 14.1-73.46; 13.1-64.29; 14.1-73.46 FIPS; 13.1.37.283 FIPS

NetScaler Gateway

Affected: before 14.1-73.46; before 13.1-64.29

Fixed: 14.1-73.46; 13.1-64.29

support.citrix.com · CVE record · NVD

What we know

Confirmed by several sources

Reported by one source

Open questions

  • It is not yet clear whether attackers are exploiting the vulnerability. — The Register

Coverage 4 publishers

  1. SecurityWeekFirst report

    Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

    The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

  2. The Hacker News

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory…

  3. BleepingComputer

    Citrix warns admins to patch new NetScaler RCE flaw immediately

    Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

  4. The Register

    Citrix gives NetScaler admins another critical reason to patch

    No word on exploitation status, but a 9.5 severity score suggests time is of the essence

Earliest report first. Articles stay on their publishers’ sites; each link opens the original.