> CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
[AUTHOR: Pierluigi Paganini]
[DATE: 09/10/2026 10:04]
[LANGUAGE: EN]
Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks.
Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
The vulnerability is caused by a memory overflow. The company says its impact depends on the system’s configuration and could allow attackers to run code remotely or disrupt services.
“CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical.” reads the report published by Citrix. “We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability. “
At this time, Citrix is not aware of attacks in the wild exploiting this vulnerability.
The following versions address the vulnerability:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later releases
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later releases of 13.1
Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP
Citrix NetScaler ADC and NetScaler Gateway are vulnerable only if they meet the following conditions: the device must be configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP), depending on the software version.
Customers can check their NetScaler configuration to see whether the appliance is set up as a SAML Service Provider (SP) or Identity Provider (IdP).
Look for one of the following entries in the configuration:
SAML Service Provider (SP): add authentication samlAction
SAML Identity Provider (IdP): add authentication samlIdPProfile
Check the Affected Versions section above for the specific requirements for each software version.
Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov reported the vulnerability to the vendor.
Recently, the company confirmed active exploitation of two other flaws, respectively tracked as CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5), on unpatched systems and urged customers to install the relevant updates as soon as possible.
This week, CISA added the flaw CVE-2026-88779 to its KeV catalog. The issue is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions. It affects certain customer-managed deployments running vulnerable versions.
“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” reads the advisory. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”
Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP). Customers can check their configuration for the relevant SAML settings.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Citrix)