Citrix Urges Immediate Patching for Critical NetScaler Vulnerability

by Ben Voss
Citrix Urges Immediate Patching for Critical NetScaler Vulnerability

Citrix is urging administrators to patch a critical vulnerability in NetScaler ADC and NetScaler Gateway appliances. The memory-overflow flaw can enable remote code execution or denial of service when affected appliances are configured for SAML authentication.

Tracked as CVE-2026-107406, the vulnerability has a CVSS 4.0 base score of 9.5. Citrix says affected deployments must be configured as a SAML service provider or identity provider, with the exact exposure depending on the installed release. Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected.

What administrators need to know

The flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group says it is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication separately.

Citrix’s recommended fixed releases are NetScaler ADC and NetScaler Gateway 14.1-73.46 or later, 13.1-64.29 or later, 14.1-73.46 FIPS or later, and 13.1.37.283 or later for 13.1-FIPS and 13.1-NDcPP deployments. Citrix said it was not aware of unmitigated exploitation of this specific vulnerability when its bulletin was published.

The Australian Signals Directorate’s Australian Cyber Security Centre updated its alert on October 9, warning organizations that earlier NetScaler patches do not address CVE-2026-107406 and recommending that they review Citrix’s latest guidance and apply the current updates.

How to check and patch a vulnerable appliance

  1. Check the configuration. Review the appliance for SAML service-provider or identity-provider settings. Citrix identifies configurations containing add authentication samlAction or add authentication samlIdPProfile as indicators that the relevant SAML roles are configured.
  2. Confirm the software release. Compare the installed build with Citrix’s affected-version ranges in the official security bulletin.
  3. Upgrade to a fixed build. Install the recommended release for the appliance’s software branch. Citrix’s NetScaler Console guidance describes how to identify impacted instances and start an upgrade workflow.
  4. Review logs after patching. Check authentication, administrative and system logs for unusual activity, unexpected configuration changes or crashes. If compromise is suspected, preserve evidence and contact Citrix support and the organization’s incident-response team.

Organizations should maintain an inventory of NetScaler appliances and their authentication roles so configuration-dependent vulnerabilities can be assessed quickly. Internet-facing access infrastructure should be patched promptly when vendor fixes are available, particularly when the device provides access to internal applications.

References