Citrix has issued a critical warning to users of its NetScaler appliances, urging them to patch a severe vulnerability that could allow attackers to execute malicious code or disrupt service. The company’s prompt notification comes on the heels of recent zero-day exploits targeting NetScaler, which have been used in attacks against various organizations.
The vulnerability, tracked as CVE-2026-107406 with a CVSS score of 9.5, is a memory overflow issue that can lead to remote code execution (RCE) or denial-of-service (DoS). This means that if an attacker exploits the flaw, they could potentially take control of a NetScaler appliance or render it unusable. The bug affects not only NetScaler ADC and Gateway appliances but also Secure Private Access Hybrid deployments that rely on these devices.
According to Citrix, the vulnerability impacts systems configured as SAML Service Providers (SP) or Identity Providers (IdP). This is significant because SAML authentication is widely used in enterprise environments for secure access management. The bug also affects NetScaler instances running specific versions of the appliance software, including 14.1-73.46 and 13.1-64.29.
Citrix has released patches to address the vulnerability, which are available as part of its latest updates for NetScaler ADC and Gateway. The company emphasizes that users should apply these patches immediately, as it is not aware of any unmitigated exploits at this time.
This warning from Citrix highlights a concerning trend in recent weeks: repeated zero-day exploits targeting NetScaler appliances. Just days ago, the company warned about CVE-2026-88779, another critical vulnerability leading to DoS. Before that, two other NetScaler zero-days were patched, and it’s clear that attackers are actively exploiting these flaws.
The severity of this situation underscores the importance of keeping software up-to-date and patching vulnerabilities promptly. As Citrix advises, users must take immediate action to prevent potential disruptions or compromises. This is particularly critical for organizations relying on SAML authentication, which may be more vulnerable to attacks due to the bug’s impact on identity providers.
To protect against this vulnerability, users should review their NetScaler configurations and apply the latest patches as soon as possible. It’s essential to stay informed about software updates and security advisories from vendors like Citrix, as these notifications often carry critical information that can prevent more severe consequences down the line.
Source: SecurityWeek — 2026-10-09