UpdatedSecurity

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

Update October 9, 2026: CISA has updated this Alert to: (1) include CVE-2026-107406; (2) include CVE-2026-88779 following its addition to the KEV Catalog on Oct. 4, 2026; (3) clarify the potential relationship between CVE-2026-88779 and CVE-2026-88771; and (4) emphasize the importance of promptly applying patches for CVE-2026-88771 through CVE-2026-88779 and CVE-2026-107406, as well as reviewing…

Read at CISA Cybersecurity Advisories

CVE-2026-107406

Severity
9.5 Critical · CVSS 4.0 · NetScaler
Exploited
Not in CISA’s catalog
Published
NetScaler ADC

Affected: before 14.1-73.46; before 13.1-64.29; before 14.1-73.46 FIPS; before 13.1.37.283 FIPS

Fixed: 14.1-73.46; 13.1-64.29; 14.1-73.46 FIPS; 13.1.37.283 FIPS

NetScaler Gateway

Affected: before 14.1-73.46; before 13.1-64.29

Fixed: 14.1-73.46; 13.1-64.29

support.citrix.com · CVE record · NVD

CVE-2026-88779Exploited

Severity
8.7 High · CVSS 4.0 · NetScaler
Exploited
Since 2026-10-04 (CISA)
CISA deadline
2026-10-07
Published
NetScaler ADC

Affected: before 14.1-73.41; before 13.1-64.28; before 14.1-73.41 FIPS; before 13.1-37.282

Fixed: 14.1-73.41; 13.1-64.28; 14.1-73.41 FIPS; 13.1-37.282

NetScaler Gateway

Affected: before 14.1-73.41; before 13.1-64.28

Fixed: 14.1-73.41; 13.1-64.28

support.citrix.com · CVE record · NVD