Citrix , known for its virtualization and networking solutions , has announced the release of security updates for a serious issue affecting NetScaler ADC and NetScaler Gateway . The vulnerability, known as CVE-2026-107406 , is a memory overflow that could lead to remote code execution or denial-of-service (DoS) under certain configuration conditions.

The severity of the vulnerability is reflected in the CVSS score of 9.5 out of 10.0, indicating the high risk it poses to affected devices.
The vulnerability has not yet been exploited by attackers, according to Citrix. However, the company acknowledges the valuable contributions of researchers Michael Tucker, Chew Keong Tan and Alex Bernier from the JPMorgan Chase XOR, as well as Maxim Suhanov, for discovering and reporting the issue. This recognition highlights the importance of collaboration between companies and security researchers to address such critical issues.
Successful exploitation of the vulnerability depends on the configuration of NetScaler installations as a SAML Identity Provider (IdP) or Service Provider (SP). Customers can check if their installations are vulnerable by examining the configuration for entries such as:
SAML SP: add authentication samlAction and
SAML IdP: add authentication samlIdPProfile.
This process is critical for understanding whether their devices are exposed to potential attacks.
See also: Citrix NetScaler RCE: Two new zero-day vulnerabilities in active exploitation

The issue affects the following versions –
When configured as a SAML IdP –
- NetScaler ADC and NetScaler Gateway versions 14.1-73.37 through 14.1-73.41
- NetScaler ADC 14.1-FIPS versions 14.1-73.37 FIPS through 14.1-73.41 FIPS
- NetScaler ADC and NetScaler Gateway versions 13.1-64.23 through 13.1-64.28
- NetScaler ADC 13.1-FIPS versions 13.1-NDcPP 13.1-37.279 through 13.1-37.282
When configured as a SAML SP or SAML IdP:
- NetScaler ADC and NetScaler Gateway versions earlier than 14.1-73.37
- NetScaler ADC 14.1-FIPS on versions prior to 14.1-73.37 FIPS
- NetScaler ADC and NetScaler Gateway versions earlier than 13.1-64.23
- NetScaler ADC 13.1-FIPS on versions prior to 13.1-NDcPP 13.1-37.279
Additionally, Citrix warned that hybrid Secure Private Access using NetScaler instances are also affected by the vulnerability. Customers of these hybrid systems should upgrade their devices to the recommended NetScaler versions to address the issue. This upgrade is necessary to protect systems from potential attacks that could exploit the vulnerability.
The issue has been addressed in the following releases –
- Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and later versions
- Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.29 and later versions of 13.1
- Citrix NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later versions of 14.1-FIPS
- Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later versions of 13.1-FIPS and 13.1-NDcPP
See also: Citrix NetScaler: CVE-2026-88779 vulnerability is actively exploited
NetScaler ADC and NetScaler Gateway vulnerabilities
The release of these updates comes at a time when three different flaws in NetScaler ADC and NetScaler Gateway appliances (CVE 2026-88771, CVE 2026-88772, and CVE 2026-88779) have already begun to be actively exploited. These vulnerabilities have raised concerns in the cybersecurity community, as attacks that exploit them can cause serious disruption to business operations.

Citrix, by releasing these updates, demonstrates its commitment to the security of its products and protecting its customers from potential threats. Organizations using NetScaler appliances are urged to take immediate action to ensure their devices are up-to-date and protected from the latest threats. Regularly updating systems and monitoring security bulletins are critical practices for maintaining security in today’s digital world.
See also: Citrix NetScaler: Creation of Superuser accounts and Web Shells via CVE-2026-88771
Addressing these vulnerabilities is crucial, as attacks that exploit such weaknesses can have devastating consequences for businesses, such as data loss, service disruption, and reputational damage. Organizations must invest in strong security policies and ensure that their IT teams are properly equipped to address cybersecurity challenges.
