Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Citrix fixes critical NetScaler vulnerability

Published 9 October 2026

Citrix has released fixes for a critical memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial of service under specific configuration conditions. The company urged customers with affected systems to install the updates as soon as possible. Citrix identified the flaw as CVE-2026-107406 and assigned it a CVSS v4.0 score of 9.5, rating it Critical. According to the company’s advisory, the vulnerability affects deployments configured with certain SAML identity-provider or service-provider roles, depending on the software version. Systems without the required configuration are not described as affected by the advisory. Citrix said it was not aware of unmitigated exploitation of this vulnerability. That statement reflects the company’s awareness; the available reporting does not independently establish whether attackers have exploited the flaw. The potential consequences cited by Citrix are disruption of services or execution of code remotely. For the 13.1 software series, Citrix recommends version 13.164.29 or later; for the 14.1 series, it recommends 14.173.46 or later. The advisory also lists version 13.1.37.

Now playing
0:00 / 0:00