Citrix gives NetScaler admins another critical reason to patch
No word on exploitation status, but a 9.5 severity score suggests time is of the essence
Citrix is urging customers to apply another critical patch for a vulnerability in NetScaler, a network application delivery platform. CVE-2026-107406 can result in remote code execution or denial of service attacks. The flaw affects both NetScaler ADC and NetScaler Gateway, with older builds posing a risk when configured as SAML service provider or identity provider.
Recent builds are vulnerable only in the identity provider configuration. Citrix has listed the affected builds and required updates on their advisory. This flaw is classified as CWE-119: improper restriction of operations within a memory buffer. Customers are responsible for updating their own deployments. Citrix handles updates for its managed cloud services and Adaptive Authentication.
The vulnerability's exploit status is unknown, but it was discovered by Michael Tucker, Chew Keong Tan, Alex Bernier from JPMorgan Chase's XOR Team, and Maxim Suhanov. Google researchers reported a campaign exploiting another CVE-2026-88772 since early September, affecting organizations in various sectors globally. Citrix disclosed this vulnerability weeks after eight others, including CVE-2026-88779, which also allows remote code execution and carries a higher severity score. Both vulnerabilities involve memory overflows in SAML configurations.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.