Citrix Urges Admins to Patch Critical NetScaler Flaw That Could Let Hackers Run Code Remotely

The vulnerability affects NetScaler ADC and Gateway appliances in specific SAML configurations and could enable remote code execution or cause service outages

Server
Citrix has urged administrators to patch vulnerable NetScaler ADC and Gateway systems after disclosing a critical flaw that could allow remote code execution Pexels

Citrix has urged administrators to update vulnerable NetScaler systems after disclosing CVE-2026-107406, a critical memory-overflow vulnerability that could allow remote code execution or denial of service.

Published on 8 October 2026, the security advisory assigns the flaw a CVSS v4.0 score of 9.5 out of 10. It affects NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances under specific software-version and SAML configuration conditions.

The vulnerability is not determined by SAML configuration alone. Certain release ranges are affected when configured as a SAML identity provider (IdP), while other earlier releases are affected when configured as either a SAML IdP or service provider (SP). Administrators should check Citrix's official advisory to determine whether their particular deployments are vulnerable.

Citrix recommends upgrading affected appliances to fixed software builds as soon as possible. The issue also affects Secure Private Access Hybrid deployments that use vulnerable NetScaler instances.

Which NetScaler Systems Are Vulnerable?

The vulnerability affects NetScaler ADC and NetScaler Gateway appliances configured as either a Security Assertion Markup Language (SAML) identity provider (IdP) or a SAML service provider (SP).

SAML is an authentication standard that allows identity providers and applications to exchange information to verify users. Organisations use it to support single sign-on, enabling employees to access multiple services without repeatedly entering their credentials.

The memory overflow flaw can potentially allow attackers to execute code remotely on a targeted device. It can also trigger a denial-of-service condition, which could cause the affected appliance to crash and disrupt services.

Citrix has also identified the issue in Secure Private Access Hybrid deployments that use NetScaler instances. Administrators managing those systems should check whether their deployments are affected and apply the recommended updates.

Citrix Releases Security Updates for Critical Flaw

Citrix has advised customers to upgrade affected appliances to the following versions:

  • NetScaler ADC and NetScaler Gateway 14.1: Version 14.1-73.46 or later.
  • NetScaler ADC and NetScaler Gateway 13.1: Version 13.1-64.29 or later in the 13.1 release branch.
  • NetScaler ADC 14.1 FIPS: Version 14.1-73.46 FIPS or later.
  • NetScaler ADC 13.1 FIPS and 13.1 NDcPP: Version 13.1.37.283 or later in the relevant release branches.

Administrators should consult Citrix's official security advisory to confirm the appropriate update for their specific deployment before making changes.

Citrix strongly recommended that affected customers review its advisory and upgrade impacted instances as soon as possible.

More Than 21,000 NetScaler Devices Have Internet-Facing Footprints

The disclosure also highlights the potential scale of exposure. Internet threat monitoring organisation Shadowserver was tracking more than 21,000 IP addresses with NetScaler fingerprints exposed online.

The figure included just over 1,500 NetScaler Gateway instances and nearly 20,000 NetScaler ADC appliances. However, these figures represent internet-visible systems identified through fingerprinting; they do not establish that every device is vulnerable to this particular flaw.

NetScaler appliances are commonly used to manage application delivery and provide secure remote access. Because they can sit at the edge of corporate networks, a compromised device could create a serious security concern for an organisation.

The precise risk depends on the appliance's configuration, software version and exposure.

Citrix Says It Has No Evidence of Unmitigated Exploitation

Despite the severity rating, Citrix said it was not aware of any unmitigated exploits of CVE-2026-107406 when it published its bulletin. That distinction matters: a critical vulnerability can present a significant risk without there being confirmed evidence that attackers are exploiting it.

The warning follows other recent security concerns involving NetScaler products, including previously disclosed vulnerabilities that were exploited in attacks. Those incidents are separate from CVE-2026-107406 and should not be taken as evidence that the newly disclosed flaw has also been exploited.

For organisations using NetScaler, the immediate priority is to establish whether their systems meet the vulnerable configuration conditions, install the appropriate updates and review their security monitoring for suspicious activity.

With thousands of NetScaler devices visible online, prompt patching and accurate asset inventories remain important steps in reducing the risk posed by critical networking vulnerabilities.