Overview
- Citrix released fixes on Friday for CVE-2026-107406, a critical memory-overflow flaw that can allow remote code execution or denial of service when NetScaler ADC or Gateway is configured as a SAML identity provider or service provider.
- The vendor published exact patched build numbers to install, including 14.1-73.46 and later and 13.1-64.29 and later, and said it was not aware of active exploitation of this specific bug at the time of the bulletin.
- Security authorities and researchers stress that which CVEs actually affect an appliance depends on its role and settings, so operators must check the running build string and whether features like SAML, DTLS or HTTP are enabled on each device.
- Because earlier NetScaler zero-days (notably CVE-2026-88771 and CVE-2026-88772) were exploited in the wild, national CERTs recommend taking memory dumps and preserving logs before upgrading so forensic teams can determine if a system was already breached.
- Internet scans show large numbers of NetScaler instances exposed online, so organisations should inventory all appliances including failovers and hybrid deployments, verify each box individually, and expect estate-wide follow-up checks for indicators of compromise.