Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions.
The vulnerability is caused by a memory overflow. The company says its impact depends on the system’s configuration and could allow attackers to run code remotely or disrupt services.
“CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions. The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical.” reads the report published by Citrix. “We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible. As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability. “
At this time, Citrix is not aware of attacks in the wild exploiting this vulnerability.
The following versions address the vulnerability:
Citrix NetScaler ADC and NetScaler Gateway are vulnerable only if they meet the following conditions: the device must be configured as a SAML Service Provider (SP) or SAML Identity Provider (IdP), depending on the software version.
Customers can check their NetScaler configuration to see whether the appliance is set up as a SAML Service Provider (SP) or Identity Provider (IdP).
Look for one of the following entries in the configuration:
add authentication samlActionadd authentication samlIdPProfileCheck the Affected Versions section above for the specific requirements for each software version.
Michael Tucker, Chew Keong Tan and Alex Bernier of the JPMorgan Chase XOR Team, and Maxim Suhanov reported the vulnerability to the vendor.
Recently, the company confirmed active exploitation of two other flaws, respectively tracked as CVE-2026-88771 (CVSS score of 9.5) and CVE-2026-88772 (CVSS score of 9.5), on unpatched systems and urged customers to install the relevant updates as soon as possible.
This week, CISA added the flaw CVE-2026-88779 to its KeV catalog. The issue is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can cause denial-of-service under specific conditions. It affects certain customer-managed deployments running vulnerable versions.
“CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions,” reads the advisory. “The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met.”
Successful exploitation requires NetScaler ADC or Gateway to be configured as a SAML service provider (SP) or identity provider (IdP). Customers can check their configuration for the relevant SAML settings.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Citrix)