Citrix Warns of Another Critical NetScaler Flaw as Patching Pressure Builds
Citrix is urging customers to patch another critical vulnerability in NetScaler ADC and NetScaler Gateway, following weeks of disclosures involving flaws that attackers were already exploiting. The new flaw, tracked as CVE-2026-107406, can lead to remote code execution or denial of service and carries a CVSS v4.0 score of 9.5. Citrix has not said whether it was exploited before disclosure.
Whether a system is affected depends on its software version and setup. Older builds are vulnerable when configured as a SAML service provider or identity provider. Some more recent builds are affected only when configured as an identity provider. Secure Private Access Hybrid deployments that use NetScaler instances also need patching. Citrix classifies the issue as a memory buffer flaw (CWE-119), and its advisory lists the affected builds and required updates. Customers must update their own deployments, while Citrix handles updates for its managed cloud services and Adaptive Authentication.
The disclosure follows other NetScaler problems. Google researchers said a campaign exploiting CVE-2026-88772 had been running since at least early September, likely affecting organisations in government, finance, legal and education across North America and Europe. Citrix also disclosed another exploited flaw, CVE-2026-88779 (severity 8.7), last Friday. Both that flaw and the new one involve memory overflows in SAML configurations, though Citrix has not identified the new one as exploited.