Friday, 9 October 2026

Patch NetScaler now to stop possible RCE on exposed devices

A critical memory-overflow vulnerability in Citrix NetScaler ADC and Gateway requires swift updates to prevent remote code execution or crashes.

Hands removing a rack-mounted enterprise ADC appliance in a data center

The short version

  • Citrix warns of a critical remote code execution risk in NetScaler ADC and Gateway (CVE-2026-107406).
  • Risk increases if devices act as SAML IdP or SP; update to the advised versions.
  • The number of exposed NetScaler devices on the internet is large, but there are no confirmed in-the-wild exploits yet.
  • Admin teams should follow the advisory, upgrade to the recommended builds, and monitor for suspicious activity.
Quick read · 1 min

Citrix has issued a warning about a new critical vulnerability in NetScaler ADC and NetScaler Gateway. The flaw, CVE-2026-107406, could let attackers run code remotely or crash the device if used as a SAML IdP or SP. Citrix provides patch paths for several version lines, including 14.1-73.46 and 13.1-64.29, plus corresponding FIPS releases.

What this means for you: if your organization uses NetScaler for remote access, inventory your devices now and patch quickly. There’s no confirmed in-the-wild exploit yet, but past NetScaler flaws have been abused, so patching is wise. After patching, monitor logs and verify access flows to ensure users connect securely. What happens next: apply the fixes listed by Citrix, then validate and monitor for any issues after the update.

  • Identify affected appliances
  • Check SAML IdP/SP configurations
  • Apply the recommended patches and test access

Citrix has issued an urgent security advisory about a fresh critical vulnerability affecting NetScaler ADC and NetScaler Gateway products. The issue, tracked as CVE-2026-107406, arises from a memory overflow and could let an attacker run code remotely or crash the device, depending on whether the appliance is configured as a SAML Identity Provider (IdP) or a SAML Service Provider (SP).

Anyone using NetScaler ADC or NetScaler Gateway in SAML IdP/SP mode should treat this as a high-priority patch. While there is no known active exploit in the wild at the moment, Citrix notes that similar NetScaler flaws have been abused in the past and urges prompt upgrades to reduce risk.

The fixes span multiple product lines. Updated versions are available for NetScaler ADC and NetScaler Gateway 14.1-73.46 and newer, and 13.1-64.29 and newer for the 13.1 line, plus corresponding FIPS releases for both 14.1 and 13.1. Citrix also lists patches for older 13.1-NDcPP and 13.1-FIPS variants. Exact update paths depend on your edition, so admins should consult the advisory for their specific model.

Shadowserver’s data shows tens of thousands of exposed NetScaler footprints on the internet, including both ADC and Gateway instances. That broad exposure helps explain why Citrix is pushing a quick patch cycle even though no proven in-the-wild exploit has been confirmed yet.

For everyday security, this means if your organization relies on NetScaler for remote access, you should inventory all affected devices, confirm whether they’re in SAML IdP or SP mode, and plan a patch window as soon as possible.

Beyond patching, review access controls around remote access, monitor for unusual activity, and limit admin access during the update window. After patching, verify that users can connect securely and that authentication flows remain intact.

Citrix has published upgrade instructions and urges admins to apply the fixes and then monitor systems for any issues. If you notice trouble after patching, contact Citrix support or your device vendor for guidance.

01

What devices are affected and how to patch

NetScaler ADC and NetScaler Gateway appliances in SAML IdP or SP configurations are affected. Use the version guidance provided by Citrix to upgrade to the correct non-FIPS or FIPS build, depending on your deployment.

Admin hands pointing to a row of network devices with clipboard in server room
02

Is there an active exploit right now?

Citrix says there were no confirmed unmitigated exploits in the wild at the time of the advisory, but previous NetScaler flaws have seen exploitation, which is why patching promptly is advised.

03

What this means for you and your wallet

The takeaway is simple: keep remote-access gear current. Patch delays can leave perimeter defenses exposed as attackers look for misconfigurations. If you manage a business network, implement a clear patch-and-verify plan to minimize downtime and maintain secure access afterward.

Office war-room table with patch instructions, closed laptop, technicians adjusting network cable
04

What happens next

Follow Citrix’s upgrade guidance and monitor logs after patching. If anything goes wrong, reach out to Citrix support and your vendor for remediation steps. Plan a brief maintenance window to ensure remote users continue to connect without issues.

05

Quick answers

What is CVE-2026-107406?

A critical memory overflow vulnerability in NetScaler ADC and Gateway that could allow remote code execution or a denial of service when configured as SAML IdP/SP.

What should I do now?

Scan for all NetScaler ADC and Gateway devices, check if they run in SAML IdP/SP mode, and apply the correct patch path to the appropriate version family as soon as possible.

You're reading the quick version.