Skip to main content
CybersecurityVulnerability Management

Citrix Warns of Immediate Patching Need for NetScaler RCE Flaw

Technicians work in a network operations room focused on a central server or network device.

CVE-2026-107406: a memory-overflow flaw in Citrix NetScaler that can allow remote code execution or crash devices into a denial-of-service state.

What the flaw is and who is exposed

Citrix has warned administrators of a critical vulnerability tracked as CVE-2026-107406 that arises from a memory overflow. Attackers exploiting the flaw can achieve remote code execution (RCE) on targeted NetScaler devices or trigger a denial-of-service (DoS) condition that causes crashes. NetScaler ADC and NetScaler Gateway appliances are only vulnerable when configured as a SAML Identity Provider (IdP) or Service Provider (SP).

Citrix's guidance and the versions to install

Citrix urged immediate patching. "We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible," the company said. "As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability."

The company specified the following upgrade targets:

  • NetScaler ADC and NetScaler Gateway 14.1-73.46 and later
  • NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP

That list is Citrix's prescribed mitigation path; the vendor's bulletin is the source of the version numbers and the urgent call to upgrade.

The exposed footprint and its uncertainties

Internet threat monitor Shadowserver reports over 21,000 public IP addresses with NetScaler fingerprints, including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances. Shadowserver's count shows a substantial potential attack surface, but the organization and Citrix both note important caveats: those addresses may include honeypots, systems already patched, or appliances with configurations that are not vulnerable.

Recent exploitation history and government tracking

Citrix emphasized this advisory against the backdrop of multiple NetScaler issues this year. In March the company urged fixes for CVE-2026-3055 and CVE-2026-4368. In September it released updates for two actively exploited RCE zero-days, CVE-2026-88771 and CVE-2026-88772, vulnerabilities that attackers used to deploy custom web shells and tunneling malware, steal credentials, gain root access, and spread into victims' internal networks. Earlier this month Citrix issued emergency updates for a NetScaler DoS zero-day, CVE-2026-88779, which researchers and administrators later said could also be exploited to gain RCE.

At the federal level, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven that were abused in ransomware attacks—an explicit measure of how frequently Citrix products have appeared in active exploitation tracking.

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams: Review NetScaler instances for SAML IdP or SP configurations and prioritize upgrades to the exact versions Citrix lists. The advisory ties vulnerability to configuration, so inventorying SAML roles is a necessary first step.
  • Affected enterprises and procurement leaders: Reconcile the organization’s NetScaler inventory against Shadowserver’s exposed-IP counts and the patch versions Citrix published; determine whether service contracts or maintenance processes need to accelerate updates to the specified releases.
  • Adversaries and threat actors: The vendor’s note that recent NetScaler RCEs have enabled web shells, tunneling, credential theft, root access, and lateral spread indicates the types of actions exploited actors have taken previously—making timely upgrades an effort to remove a high-value entry vector.

Citrix reports no known unmitigated exploitation of CVE-2026-107406 at the time of the bulletin, but the combination of a large public-facing footprint, a configuration-based attack surface, and a string of earlier NetScaler zero-days makes the vendor’s urgent upgrade recommendation notable: organizations running SAML-enabled NetScaler ADC or Gateway appliances have a specific list of versions to install, and an observable internet population that merits immediate attention.

https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/