Citrix issues urgent NetScaler patch warning for critical remote code execution flaw

Citrix has issued an urgent advisory for a critical NetScaler ADC and NetScaler Gateway vulnerability tracked as CVE-2026-107406. The memory overflow flaw can let attackers run code remotely or cause a denial-of-service, and systems are affected when configured as SAML identity or service providers. Administrators are told to upgrade to the recommended releases, though Citrix says it has not seen unmitigated exploitation yet.
Citrix’s notice covers NetScaler ADC appliances and NetScaler Gateway remote-access products. The bug, CVE-2026-107406, arises from a memory overflow and could permit remote code execution or a denial-of-service condition. Only deployments acting as SAML identity providers or service providers are described as vulnerable.
The vendor listed fixed builds across 14.1, 13.1, FIPS, and NDcPP branches. Shadowserver data cited in the report counts more than 21,000 internet-facing NetScaler fingerprints, though it is unclear how many are honeypots, already updated, or configured in a risky way. Citrix said it had not seen exploitation that bypassed available mitigations.
Organizations using vulnerable NetScaler ADC or Gateway systems for SAML authentication or remote access could face service outages or network compromise if the flaw is exploited. Because these appliances often sit at the edge of corporate networks, a successful attack may expose credentials, internal applications, and user data. The practical impact may depend on how quickly administrators apply fixes and whether exposed instances are configured as SAML providers. Smaller IT teams with limited patching resources could be especially strained.