{
  "id": 13104815,
  "title": "Citrix gives NetScaler admins another critical reason to patch",
  "url": "https://urgent.news/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T11:43:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212"
  },
  "original_language": "en",
  "account": "Citrix is urging customers to apply another critical patch for a vulnerability in NetScaler, a network application delivery platform. CVE-2026-107406 can result in remote code execution or denial of service attacks. The flaw affects both NetScaler ADC and NetScaler Gateway, with older builds posing a risk when configured as SAML service provider or identity provider. Recent builds are vulnerable only in the identity provider configuration. Citrix has listed the affected builds and required updates on their advisory. This flaw is classified as CWE-119: improper restriction of operations within a memory buffer. Customers are responsible for updating their own deployments. Citrix handles updates for its managed cloud services and Adaptive Authentication. The vulnerability's exploit status is unknown, but it was discovered by Michael Tucker, Chew Keong Tan, Alex Bernier from JPMorgan Chase's XOR Team, and Maxim Suhanov. Google researchers reported a campaign exploiting another CVE-2026-88772 since early September, affecting organizations in various sectors globally. Citrix disclosed this vulnerability weeks after eight others, including CVE-2026-88779, which also allows remote code execution and carries a higher severity score. Both vulnerabilities involve memory overflows in SAML configurations.",
  "summary": "No word on exploitation status, but a 9.5 severity score suggests time is of the essence",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "After the patch: verifying remediation for CVE-2026-88772 on NetScaler ADC and Gateway",
        "url": "https://urgent.news/2026/10/08/after-the-patch-verifying-remediation-for-cve-2026-88772-on-netscaler",
        "published": "2026-10-08T16:00:37.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "Citrix gives NetScaler admins another critical reason to patch",
        "url": "https://urgent.news/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch-13109490",
        "published": "2026-10-09T11:43:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}