Citrix has released fixes for a critical flaw in NetScaler ADC and NetScaler Gateway, according to its security bulletin. The flaw is tracked as CVE-2026-107406. The Hacker News reported on 9 October that Citrix calls it a memory overflow bug. Under specific settings, it may lead to remote code execution or a denial of service, meaning the device stops working. The Hacker News gave it a severity score of 9.5 out of 10. Only devices set up for SAML, a single sign-on standard, are exposed. Fixed releases start at 14.1-73.46 and 13.1-64.29, with separate FIPS builds.
The Hacker News said there is no evidence that anyone has exploited this flaw in the wild. The sources do not explain how an attacker would use the bug. Credit for finding it differs between the two reports. Citrix names Joshua Foote, Michael Tucker and Eugene Lim of the JPMorgan Chase XOR Team. The Hacker News says Citrix credited Michael Tucker, Chew Keong Tan and Alex Bernier of that team, plus Maxim Suhanov. The Hacker News also reported that three other NetScaler flaws are being exploited now.
Teams that run their own NetScaler appliances should check whether they use SAML, since Citrix ties the flaw to those settings. Citrix says Secure Private Access Hybrid setups using NetScaler are affected too, while Cloud Software Group updates Citrix-managed cloud services itself.