A Critical Vulnerability Hits NetScaler Appliances, Leaving Users Exposed to Remote Code Execution Attacks
Citrix has issued an urgent warning to administrators of its NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. A newly discovered vulnerability, tracked as CVE-2026-107406, allows attackers to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes.
The flaw stems from a memory overflow weakness in systems configured as Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP). This configuration is common in many organizations, particularly those using NetScaler for secure remote access and load balancing. The vulnerability affects NetScaler ADC and NetScaler Gateway appliances running various versions of the software.
Citrix has taken swift action to address the issue by releasing patched versions of its software. Affected customers are advised to review the company’s advisory and upgrade their vulnerable instances to the recommended versions as soon as possible. Citrix has not reported any confirmed cases of exploitation, but given the severity of the vulnerability, it is crucial that users take immediate action.
The affected systems include:
* NetScaler ADC and NetScaler Gateway 14.1-73.46 and later
* NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1
* NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
* NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP
A significant number of organizations may be affected by this vulnerability, as Shadowserver estimates that over 21,000 IP addresses with NetScaler fingerprints are exposed on the Internet. However, it is unclear how many systems have already been patched or have vulnerable configurations.
This incident highlights a worrying trend in Citrix’s products, which has seen several vulnerabilities exploited by attackers since the start of the year. In March, Citrix warned users about two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) just before threat actors began abusing them. More recently, the company released security updates for two actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that allowed attackers to deploy custom web shells and tunneling malware.
To protect themselves from this vulnerability and similar threats in the future, organizations should prioritize regular software updates and patch management. This includes staying informed about known vulnerabilities and applying patches as soon as possible. In addition, administrators should ensure they have robust security protocols in place, including monitoring for suspicious activity and implementing network segmentation to limit the potential damage of a successful attack.
Ultimately, this incident serves as a reminder that even the most secure systems can be vulnerable to exploitation if not properly maintained. By taking proactive steps to address vulnerabilities and stay informed about emerging threats, organizations can reduce their risk of being targeted by attackers.
Source: Bleeping Computer — 2026-10-09