Overview
- Citrix released fixes Friday for CVE-2026-107406, a memory overflow in NetScaler ADC and Gateway that can cause remote code execution or denial of service when the appliance is configured as a SAML identity provider or service provider.
- The company provided specific fixed builds for affected branches and urged immediate upgrades to the listed versions to stop new exploitation.
- Citrix said it is not aware of unmitigated in-the-wild exploitation of CVE-2026-107406 but warned that earlier NetScaler flaws were actively abused to deploy web shells, tunneling tools, and techniques for persistent root access.
- Security guidance from national CERTs and researchers calls for operators to first preserve logs and take memory dumps, then apply the patch, and to rotate credentials and keys if a prior compromise is suspected.
- Large internet scans show tens of thousands to hundreds of thousands of externally reachable NetScaler instances, so configuration-dependent exposure creates a wide potential blast radius for both targeted attackers and opportunistic scanners.