Citrix gives NetScaler admins another critical reason to patch
No word on exploitation status, but a 9.5 severity score suggests time is of the essence
Citrix has advised customers to patch yet another critical flaw in NetScaler, following a series of disclosed vulnerabilities with active exploitation. CVE-2026-107406 impacts NetScaler ADC and NetScaler Gateway, posing the risk of remote code execution (RCE) or denial of service (DoS) attacks. The severity of this issue is rated 9.5 on the CVSS v4.0 scale.
The vulnerability's impact varies based on the software version, with older builds susceptible when utilized as a SAML service provider (SP) or identity provider (IdP); certain newer builds are vulnerable exclusively in the identity provider configuration. Citrix has detailed the impacted builds and the corresponding updates required.
Secure Private Access Hybrid environments employing NetScaler instances also necessitate patching. Citrix categorizes this flaw as CWE-119, which denotes an improper restriction of operations within a memory buffer. It falls to the customers to undertake the necessary updates for their own deployments. Citrix ensures that its managed cloud services and Adaptive Authentication undergo the required updates.
While there is no confirmation of this vulnerability being exploited as a zero-day prior to disclosure, Citrix acknowledges the discovery to Michael Tucker, Chew Keong Tan, and Alex Bernier from JPMorgan Chase's XOR Team, and Maxim Suhanov. Google researchers reported a campaign exploiting CVE-2026-88772 since early September, which likely affected entities in the government, finance, legal, and education sectors across North America and Europe.
Citrix unveiled the flaw weeks later as part of an update encompassing eight vulnerabilities. Last Friday, Citrix disclosed another exploited flaw, CVE-2026-88779, with a severity score of 8.7. This flaw and the newly disclosed vulnerability both stem from memory overflows affecting SAML configurations. The latter also enables remote code execution, carries a higher severity score, and has not been flagged by Citrix as a previously exploited vulnerability.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.