Citrix has released security updates to address a critical vulnerability affecting NetScaler ADC and NetScaler Gateway appliances that could allow remote code execution or trigger denial of service under specific deployment conditions. Tracked as CVE-2026-107406, the flaw has received a CVSS severity score of 9.5 out of 10, highlighting the significant risk it poses to organizations using affected products. According to Citrix, the issue is a memory overflow vulnerability that can be exploited only when NetScaler devices are configured to function as a Security Assertion Markup Language (SAML) identity provider or service provider. While the company emphasized that there is currently no evidence of active exploitation in real world environments, it has urged customers to install the latest security updates as soon as possible to reduce potential exposure.
The vulnerability was identified and responsibly reported by Michael Tucker, Chew Keong Tan, and Alex Bernier from the JPMorgan Chase XOR Team, together with security researcher Maxim Suhanov. Citrix noted that administrators can determine whether their deployments are affected by reviewing their appliance configuration for SAML authentication entries associated with either SAML service provider or SAML identity provider functionality. The issue impacts multiple versions of NetScaler ADC and NetScaler Gateway across both standard and FIPS editions. Systems configured as SAML identity providers running several releases within the 14.1 and 13.1 branches are affected, while other deployments operating as either SAML service providers or identity providers on earlier supported versions are also vulnerable. Citrix further confirmed that Secure Private Access Hybrid deployments using NetScaler instances are included within the scope of the vulnerability, making it important for organizations operating hybrid access environments to verify their installations and apply the recommended software updates.
To address the issue, Citrix has released updated software versions across all supported product branches. The company recommends upgrading NetScaler ADC and NetScaler Gateway deployments to version 14.1-73.46 or later, or version 13.1-64.29 and newer for the 13.1 release line. Updated releases have also been made available for FIPS and NDcPP editions, including version 14.1-73.46 FIPS and version 13.1.37.283 or later. Applying these updates removes the vulnerability and helps protect systems configured for SAML authentication against potential remote code execution or denial of service attempts. Although no confirmed attacks exploiting CVE-2026-107406 have been reported, prompt patch management remains an important security practice, particularly for internet facing authentication infrastructure that plays a critical role in enterprise identity and access management.
The latest security advisory comes amid continued attention on NetScaler security after several other vulnerabilities affecting the platform entered active exploitation in recent weeks. Citrix has previously disclosed CVE-2026-88771, CVE-2026-88772, and CVE-2026-88779, each involving separate security issues impacting NetScaler ADC and NetScaler Gateway appliances. Those earlier vulnerabilities have been observed in exploitation campaigns, increasing the urgency for organizations to maintain current software versions and regularly review their security posture. While CVE-2026-107406 has not been linked to any known exploitation activity at this time, the release of patches provides organizations with an opportunity to strengthen their defenses before any potential misuse emerges. Security teams are encouraged to review appliance configurations, verify whether SAML functionality is enabled, and implement the recommended updates without unnecessary delay to minimize operational risk and maintain the integrity of authentication services.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.