Skip to content
feed: live
0dayNews
citrix

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now

CVE-2026-107406, CVSS 9.5, is a memory overflow in Citrix NetScaler that allows unauthenticated RCE or DoS in SAML-configured deployments. Patch now.

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now
Photo: Alexey Komarov / Wikimedia Commons · CC BY 3.0
fuseMarisol "Fuse" Delgado·Published ·1 min read

Citrix released security bulletin CTX697191 disclosing CVE-2026-107406, a CVSS 9.5 critical memory overflow in NetScaler ADC and NetScaler Gateway. Successful exploitation allows unauthenticated remote code execution (RCE) or denial of service. Patched builds are available and Citrix is urging immediate deployment.

Who is affected

The flaw is present when NetScaler is configured as a SAML Service Provider (SP) or Identity Provider (IdP), or in Secure Private Access Hybrid deployments. The CTX697191 bulletin lists the specific build numbers and patched targets for the 14.1, 13.1, and FIPS branches. Deployments not using SAML SP, SAML IdP, or Secure Private Access Hybrid have reduced exposure, but Citrix still recommends applying the patch.

Citrix states it has no confirmed reports of active exploitation as of the advisory’s publication date.

What to do

Check CTX697191 for the exact target build for your branch and upgrade now. This is not a case where “we’re not SAML” means you can defer: SAML is enabled by default in many configurations, and the no-exploitation-confirmed window has closed fast on every prior NetScaler advisory this fall.

Fourth NetScaler advisory in days

This disclosure follows three others in quick succession. CVE-2026-88779 was patched on October 5 after active exploitation confirmed against government and financial-sector targets. CVE-2026-88771 and CVE-2026-88772 were patched on September 28, with CVE-2026-88772 driving a web shell campaign that CISA flagged before the KEV deadline. All three reached CISA’s Known Exploited Vulnerabilities catalog after initially carrying a “no known exploitation” status.

For the full version matrix and any available workarounds, see the Citrix CTX697191 bulletin and the NVD entry for CVE-2026-107406.

Related CVEs
  • [ CRITICAL ]CVE-2026-107406Memory overflow in Citrix NetScaler ADC and Gateway SAML handling

Found this useful? Share it.