
Citrix Urges Immediate Fixes For Critical NetScaler Vulnerability With High Risk Score
Security teams must update their systems to close a critical memory error in recent software versions.
9 Oct 2026
Citrix releases security updates to fix a dangerous flaw tracked as CVE-2026-107406 in its NetScaler network products. This applies to both the ADC appliance and the Gateway service used by many enterprises.
The issue carries a CVSS score of 9.5, which marks it as a critical risk level for users. Experts agree this rating indicates a high severity that requires fast action from system administrators.
Hackers could exploit the memory overflow to run their own code or cause service disruptions on the device. The actual damage depends heavily on how each customer has configured their specific NetScaler hardware settings.
Only certain setups are vulnerable because the flaw requires specific identity management features to be active. The risk applies when the system operates as a SAML Service Provider or an Identity Provider for users.
This setting allows different platforms to share login credentials securely without creating new passwords for every connection. Systems acting in these roles face exposure due to the software error within that specific module.

Users with Secure Private Access Hybrid deployments that use NetScaler infrastructure are also covered by this warning. They should verify their configuration files to determine if they fall into the affected category.
Patches are available in newer versions like release 14.1-73.46 and any updates released after that point. Owners on older lines must upgrade to at least version 13.1-64.29 or the specific FIPS builds.
The company says it is not aware of active attacks exploiting this exact vulnerability in real-world environments yet. Despite this, officials urge customers to review their systems and apply the fix immediately to stay safe.
This warning comes shortly after reports of other zero-days being used against government and financial groups recently. Those earlier incidents involved similar flaws that allowed remote control or denial of service on unpatched machines.
The discovery was credited to researchers from JPMorgan Chase XOR Team and security expert Maxim Suhanov. Their report reached the vendor early in October 2026, leading to these emergency release notes for customers.