LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has issued an urgent advisory to administrators regarding a new critical vulnerability, tracked as CVE-2026-107406, affecting its NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. The company is urging immediate patching to mitigate the risk of remote code execution (RCE) or denial-of-service (DoS) attacks.

ZeroDay News ·

Source: BleepingComputer

Citrix has issued an urgent advisory to administrators regarding a new critical vulnerability, tracked as CVE-2026-107406, affecting its NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. The company is urging immediate patching to mitigate the risk of remote code execution (RCE) or denial-of-service (DoS) attacks.

The vulnerability is described as a memory overflow weakness. Exploitation of this flaw could allow attackers to execute arbitrary code on affected devices or trigger a DoS state, leading to system crashes. For an appliance to be vulnerable, it must be configured as either a Security Assertion Markup Language (SAML) Identity Provider (IdP) or a Service Provider (SP).

Citrix has confirmed that it is not aware of any active exploitation of CVE-2026-107406 in the wild as of the publication of its security bulletin. However, the company strongly recommends that all affected customers review the advisory and upgrade their NetScaler instances without delay.

The recommended versions to address this vulnerability are: NetScaler ADC and NetScaler Gateway 14.1-73.46 and later; NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1; NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP.

Internet monitoring services have identified over 21,000 IP addresses with NetScaler fingerprints exposed online. This includes approximately 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances. It is currently unknown how many of these exposed instances are honeypots, have already been patched, or are configured in a vulnerable manner.

This latest warning follows a series of critical NetScaler vulnerabilities that have been actively exploited throughout the year. In March, Citrix advised customers to patch CVE-2026-3055 and CVE-2026-4368, which were subsequently abused by threat actors. More recently, in September, emergency security updates were released for two actively exploited NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772. These flaws allowed attackers to deploy custom web shells, install tunneling malware, steal credentials, gain root access, and infiltrate internal networks.

Earlier this month, Citrix also issued emergency updates for CVE-2026-88779, a NetScaler denial-of-service zero-day. Researchers and administrators later indicated that this particular flaw could also be leveraged for remote code execution. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, with seven of these being abused in ransomware attacks.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Anthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT Security

Anthropic has reportedly initiated a program to fast-track AI-generated vulnerability reports to open-source software (OSS) maintainers. This new system, dubbed "OSS Scanner," is designed to automatically generate and dispatch bug reports. The reports are sent directly to maintainers who have opted into the program, raising questions about the review process for these AI-generated findings.

vulnerability

Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland

The Pwn2Own Ireland 2026 hacking competition concluded with security researchers earning a total of $1,262,000 for demonstrating 98 unique zero-day vulnerabilities across various products. The three-day event, organized by Trend Micro's Zero Day Initiative (ZDI), saw 29 research teams targeting devices in seven categories, including mobile phones, AI infrastructure, and smart home devices.

aicritical

AI Training Critical as Governance Challenges Grow

Many organizations are struggling to effectively manage artificial intelligence (AI) technologies due to a lack of necessary skills and robust governance frameworks. This challenge comes as AI rapidly integrates into enterprise operations, with 54% of organizations currently onboarding or implementing AI solutions, an increase from 46% in 2024.

security

Product showcase: SimpleLogin keeps your email address private with aliases

SimpleLogin, an email alias service developed by Proton, allows users to create unique, disposable email addresses that forward messages to a primary inbox. This system is designed to enhance privacy by limiting the exposure of a user's main email address across various online services.

nation-statecritical

US Disrupts Chinese State-Sponsored Hacking Tools

The United States government has reportedly disrupted a set of hacking tools attributed to Chinese state-sponsored advanced persistent threat (APT) groups, including one known as Flax Typhoon. These tools, identified as MicroScan and FishHub, were reportedly employed in campaigns targeting critical infrastructure within the U.S. and other nations. The disruption aims to mitigate ongoing…

ai

Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push

Ten prominent AI companies have committed to enhancing their data protection practices in the UK following a push from the Information Commissioner's Office (ICO), the country's privacy watchdog. Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI, and Stability AI are among the firms that have pledged to implement changes, which include improving transparency,…