Citrix Urges Immediate Patching of Critical NetScaler Flaw
Citrix warned of a critical NetScaler vulnerability, CVE-2026-107406 (CVSS 9.5), a memory overflow that could lead to remote code execution or denial-of-service. Patches are available in NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29 and FIPS builds; no exploits are known yet.
- CVE-2026-107406 carries a CVSS score of 9.5 — critical severity
- Affects NetScaler ADC and Gateway configured as SAML SP or SAML IdP
- Patched in 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, 13.1.37.283
- Citrix says it is not aware of any unmitigated exploits
Read next
Security