Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

Tracked as CVE-2026-107406, this flaw stems from a memory overflow weakness that attackers can exploit to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes.

To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP).

"We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible," the company said. "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability."

Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:

  • NetScaler ADC and NetScaler Gateway 14.1-73.46 and later,
  • NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP

Internet threat watchdog Shadowserver tracks over 21,000 IP addresses with NetScaler fingerprints exposed on the Internet (including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances).

However, at the time, there is no information on how many are honeypots, have already been patched, or have vulnerable configurations.

Internet-exposed NetScaler appliances
Internet-exposed NetScaler appliances (Shadowserver)

While Citrix has not found evidence that attackers have begun exploiting CVE-2026-107406 in the wild, the company warned of several other NetScaler vulnerabilities that attackers have abused since the start of the year.

For instance, in March, Citrix urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.

More recently, in September, it released security updates for two more actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access, and spread into victims' internal networks.

Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dive deeper

Free tools to verify and analyze what this article covers:

source: BleepingComputer