The vulnerability affects NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions configured as a Security Assertion Markup Language (SAML) Identity Provider or Service Provider. Citrix released fixed versions: NetScaler ADC and Gateway 14.1-73.46 and later, 13.1-64.29 and later, and FIPS/NDcPP variants. The company said it is not aware of any unmitigated exploitation of the flaw, but noted that other NetScaler vulnerabilities have been actively exploited in attacks since the start of the year. In March, Citrix urged customers to patch two other NetScaler issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.
Internet threat watchdog Shadowserver tracks more than 21,000 exposed NetScaler instances online, including approximately 1,500 Gateway devices and nearly 20,000 ADC appliances. It is unclear how many are honeypots, already patched, or possess vulnerable configurations. Citrix reiterated: "We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible."