Citrix warns of critical NetScaler RCE flaw, urges immediate patching

Memory overflow vulnerability CVE-2026-107406 could allow attackers to take over remote access appliances

By LineZotpaper
Published
Read Time2 min
Citrix has issued an urgent advisory urging IT administrators to patch a critical remote code execution vulnerability in NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-107406, the flaw stems from a memory overflow weakness and can be exploited on devices configured as SAML identity providers or service providers. While Citrix has not observed active exploitation, it strongly recommends upgrading to patched versions immediately.

The vulnerability affects NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions configured as a Security Assertion Markup Language (SAML) Identity Provider or Service Provider. Citrix released fixed versions: NetScaler ADC and Gateway 14.1-73.46 and later, 13.1-64.29 and later, and FIPS/NDcPP variants. The company said it is not aware of any unmitigated exploitation of the flaw, but noted that other NetScaler vulnerabilities have been actively exploited in attacks since the start of the year. In March, Citrix urged customers to patch two other NetScaler issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them.

Internet threat watchdog Shadowserver tracks more than 21,000 exposed NetScaler instances online, including approximately 1,500 Gateway devices and nearly 20,000 ADC appliances. It is unclear how many are honeypots, already patched, or possess vulnerable configurations. Citrix reiterated: "We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible."

§

Analysis

Why This Matters

  • Over 21,000 NetScaler appliances are exposed on the internet, representing a large attack surface.
  • The flaw can be exploited for remote code execution, giving attackers full control of the device, or trigger denial of service.
  • Given that similar NetScaler vulnerabilities have been exploited in the past, timely patching is critical.

Background

Citrix NetScaler products provide application delivery, load balancing, and secure remote access for enterprises. The current flaw affects configurations where the appliance acts as a SAML identity provider or service provider, a common setup for federated authentication. Citrix has released patches for previous critical vulnerabilities this year, some of which were exploited before many organizations could update.

Key Perspectives

IT Administrators: They face a race to patch exposed appliances while minimizing disruption to business operations. Citrix: The company has released patches and is urging swift action to prevent exploitation without confirming active attacks. Security Researchers: They are monitoring for signs of exploitation and assessing the exposure of vulnerable devices worldwide.

What to Watch

  • Shadowserver's tracking of exposed NetScaler IPs as a measure of patch adoption.
  • Whether proof-of-concept code or active exploitation emerges in the coming days.
  • Citrix's next security advisory if the vulnerability is actively exploited.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe