Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has issued a critical warning to IT administrators, urging them to patch their NetScaler ADC and NetScaler Gateway appliances immediately to prevent remote code execution (RCE) attacks. The vulnerability, tracked as CVE-2026-107406, allows attackers to gain control over targeted devices or trigger denial-of-service (DoS) states that can cause crashes.

To be vulnerable, NetScaler appliances must be configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP). This means that any organization using these configurations is at risk. Citrix has not found evidence of attacks exploiting this vulnerability in the wild, but warns that it’s only a matter of time before attackers start to target vulnerable systems.

The company advises customers to upgrade their NetScaler instances to the recommended versions as soon as possible. The affected appliances include NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1, NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS, and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP.

The fact that this vulnerability has been discovered at all is a reminder of the ongoing threat landscape facing organizations using Citrix NetScaler appliances. Shadowserver, an internet threat watchdog, estimates that over 21,000 IP addresses with NetScaler fingerprints are exposed on the Internet, including nearly 20,000 NetScaler ADC instances and just over 1,500 Gateway instances. However, it’s unclear how many of these systems have already been patched or have vulnerable configurations.

Citrix has a history of issuing warnings for critical vulnerabilities in their products, only to see attackers begin exploiting them soon after. In March, the company urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) just days before threat actors began abusing them. More recently, Citrix released security updates for two actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772), which allowed attackers to deploy custom web shells and tunneling malware.

Given the history of vulnerabilities in Citrix products, it’s essential that IT administrators take this warning seriously and patch their systems immediately. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks. By taking prompt action to address this vulnerability, organizations can help prevent a potentially catastrophic attack on their networks.

In conclusion, the discovery of CVE-2026-107406 highlights the importance of regular security patching and monitoring for critical infrastructure systems like Citrix NetScaler appliances. IT administrators should review the advisory and upgrade their systems to recommended versions as soon as possible to minimize the risk of RCE attacks.


Source: Bleeping Computer — 2026-10-09