Vulnerabilities

Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

Citrix vulnerability

Citrix on Thursday warned users of a critical-severity NetScaler vulnerability that requires immediate patching.

Tracked as CVE-2026-107406 (CVSS score of 9.5), the flaw is described as a memory overflow that could lead to remote code execution (RCE) or denial-of-service (DoS).

According to Citrix, the security defect impacts NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP or SAML IdP, under specific configuration conditions.

The bug also affects Secure Private Access Hybrid deployments that use NetScaler. Customers need to update these NetScaler instances as well.

Patches were included in NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (of 13.1-FIPS and 13.1-NDcPP).

“As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability,” Citrix notes, urging customers to upgrade their instances as soon as possible.

Advertisement. Scroll to continue reading.

Citrix’s fresh warning comes days after the company sounded the alarm on CVE-2026-88779, a zero-day in NetScaler leading to DoS.

A week before, two other NetScaler zero-days were patched: CVE-2026-88771 (leading to RCE), and CVE-2026-88772 (leading to RCE or DoS). They have been exploited in attacks against government, financial services, education, legal, and professional services organizations.

Related: Critical NetScaler Vulnerability Exploited in Attacks

Related: Cisco Patches a Dozen Critical Vulnerabilities

Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

Related: SonicWall and Splunk Patch Critical Vulnerabilities

Related Content

Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Vulnerabilities

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Vulnerabilities

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

Cybercrime

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version