Citrix is urging administrators to patch a critical vulnerability in NetScaler ADC and NetScaler Gateway appliances. The memory-overflow flaw can enable remote code execution or denial of service when affected appliances are configured for SAML authentication.
Tracked as CVE-2026-107406, the vulnerability has a CVSS 4.0 base score of 9.5. Citrix says affected deployments must be configured as a SAML service provider or identity provider, with the exact exposure depending on the installed release. Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected.
What administrators need to know
The flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances. Cloud Software Group says it is updating Citrix-managed cloud services and Citrix-managed Adaptive Authentication separately.
Citrix’s recommended fixed releases are NetScaler ADC and NetScaler Gateway 14.1-73.46 or later, 13.1-64.29 or later, 14.1-73.46 FIPS or later, and 13.1.37.283 or later for 13.1-FIPS and 13.1-NDcPP deployments. Citrix said it was not aware of unmitigated exploitation of this specific vulnerability when its bulletin was published.
The Australian Signals Directorate’s Australian Cyber Security Centre updated its alert on October 9, warning organizations that earlier NetScaler patches do not address CVE-2026-107406 and recommending that they review Citrix’s latest guidance and apply the current updates.
How to check and patch a vulnerable appliance
- Check the configuration. Review the appliance for SAML service-provider or identity-provider settings. Citrix identifies configurations containing
add authentication samlActionoradd authentication samlIdPProfileas indicators that the relevant SAML roles are configured. - Confirm the software release. Compare the installed build with Citrix’s affected-version ranges in the official security bulletin.
- Upgrade to a fixed build. Install the recommended release for the appliance’s software branch. Citrix’s NetScaler Console guidance describes how to identify impacted instances and start an upgrade workflow.
- Review logs after patching. Check authentication, administrative and system logs for unusual activity, unexpected configuration changes or crashes. If compromise is suspected, preserve evidence and contact Citrix support and the organization’s incident-response team.
Organizations should maintain an inventory of NetScaler appliances and their authentication roles so configuration-dependent vulnerabilities can be assessed quickly. Internet-facing access infrastructure should be patched promptly when vendor fixes are available, particularly when the device provides access to internal applications.
References
- Arghire, I. (2026, October 9). Citrix urges immediate patching of critical NetScaler vulnerability. SecurityWeek. https://www.securityweek.com/citrix-urges-immediate-patching-of-critical-netscaler-vulnerability/
- Australian Signals Directorate’s Australian Cyber Security Centre. (2026, October 9). Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products. https://www.cyber.gov.au/alert/critical-vulnerabilities-in-citrix-netscaler-adc-and-citrix-netscaler-gateway-products
- Citrix. (2026, October 8). Citrix NetScaler ADC and Citrix NetScaler Gateway security bulletin for CVE-2026-107406. https://support.citrix.com/external/article/CTX697191/citrix-netscaler-adc-and-citrix-netscale.html
- Citrix. (2026, October 8). Identify and remediate vulnerabilities for CVE-2026-107406. NetScaler Documentation. https://docs.netscaler.com/us/en/netscaler-console-service/remediate-vulnerabilities-cve-2026-107406.html
- Gatlan, S. (2026, October 9). Citrix warns admins to patch new NetScaler RCE flaw immediately. BleepingComputer. https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/
