Citrix has issued an urgent advisory to administrators regarding a new critical vulnerability, tracked as CVE-2026-107406, affecting its NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. The company is urging immediate patching to mitigate the risk of remote code execution (RCE) or denial-of-service (DoS) attacks.
The vulnerability is described as a memory overflow weakness. Exploitation of this flaw could allow attackers to execute arbitrary code on affected devices or trigger a DoS state, leading to system crashes. For an appliance to be vulnerable, it must be configured as either a Security Assertion Markup Language (SAML) Identity Provider (IdP) or a Service Provider (SP).
Citrix has confirmed that it is not aware of any active exploitation of CVE-2026-107406 in the wild as of the publication of its security bulletin. However, the company strongly recommends that all affected customers review the advisory and upgrade their NetScaler instances without delay.
The recommended versions to address this vulnerability are: NetScaler ADC and NetScaler Gateway 14.1-73.46 and later; NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1; NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP.
Internet monitoring services have identified over 21,000 IP addresses with NetScaler fingerprints exposed online. This includes approximately 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances. It is currently unknown how many of these exposed instances are honeypots, have already been patched, or are configured in a vulnerable manner.
This latest warning follows a series of critical NetScaler vulnerabilities that have been actively exploited throughout the year. In March, Citrix advised customers to patch CVE-2026-3055 and CVE-2026-4368, which were subsequently abused by threat actors. More recently, in September, emergency security updates were released for two actively exploited NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772. These flaws allowed attackers to deploy custom web shells, install tunneling malware, steal credentials, gain root access, and infiltrate internal networks.
Earlier this month, Citrix also issued emergency updates for CVE-2026-88779, a NetScaler denial-of-service zero-day. Researchers and administrators later indicated that this particular flaw could also be leveraged for remote code execution. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, with seven of these being abused in ransomware attacks.






