Citrix: Critical Citrix NetScaler Vulnerability Allows Remote Code Execution and DoS Attacks

Citrix: Critical Citrix NetScaler Vulnerability Allows Remote Code Execution and DoS Attacks

Critical Citrix NetScaler Vulnerability (CVE-2026-107406) Exposes Systems to RCE and DoS Risks

Citrix has disclosed a severe memory overflow vulnerability in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406, with a CVSS v4.0 score of 9.5. The flaw could enable remote code execution (RCE) or denial-of-service (DoS) attacks under specific configurations, prompting urgent upgrades for affected deployments.

Affected Systems and Conditions

Exposure depends on software version and SAML configuration:

  • Newer builds (e.g., 14.1-73.37 to 14.1-73.41, 13.1-64.23 to 13.1-64.28) are vulnerable only if configured as a SAML identity provider (IdP).
  • Older builds (e.g., pre-14.1-73.37, pre-13.1-64.23) are vulnerable if configured as either a SAML service provider (SP) or IdP.
  • FIPS/NDcPP builds (e.g., 14.1-73.37 FIPS to 14.1-73.41 FIPS, 13.1-37.279 to 13.1-37.282) follow similar version-based exposure rules.

Administrators must verify SAML configurations via CLI commands:

  • add authentication samlAction → SAML SP
  • add authentication samlIdPProfile → SAML IdP

Scope and Mitigation

  • Citrix-managed cloud services and Adaptive Authentication are not affected, as Citrix applies updates automatically.
  • Customer-managed environments must upgrade to fixed builds (refer to security bulletin CTX697191 for exact versions).
  • Secure Private Access Hybrid deployments using affected NetScaler instances also require upgrades.

Current Threat Status

Citrix reports no known active exploits at the time of disclosure. The advisory does not detail the technical mechanism, exploitation steps, or indicators of compromise (IoCs), limiting insights into attack feasibility or authentication requirements.

Organizations are advised to prioritize patching based on version and configuration to mitigate potential RCE or DoS risks.

Source: https://cyberpress.org/critical-citrix-netscaler-vulnerability-allows-remote-code-execution-and-dos-attacks/

Citrix TPRM report: https://www.rankiteo.com/company/citrix

"id": "cit1791534579",
"linkid": "citrix",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations using affected '
                                              'NetScaler ADC and NetScaler '
                                              'Gateway versions',
                        'industry': 'Technology/Software',
                        'name': 'Citrix',
                        'type': 'Vendor'}],
 'attack_vector': 'Remote',
 'customer_advisories': 'Verify SAML configurations and apply patches '
                        'immediately to mitigate RCE or DoS risks.',
 'description': 'Citrix has disclosed a severe memory overflow vulnerability '
                'in NetScaler ADC and NetScaler Gateway, tracked as '
                'CVE-2026-107406, with a CVSS v4.0 score of 9.5. The flaw '
                'could enable remote code execution (RCE) or denial-of-service '
                '(DoS) attacks under specific configurations, prompting urgent '
                'upgrades for affected deployments.',
 'impact': {'operational_impact': 'Potential remote code execution (RCE) or '
                                  'denial-of-service (DoS)',
            'systems_affected': 'NetScaler ADC and NetScaler Gateway'},
 'investigation_status': 'No known active exploits at time of disclosure',
 'post_incident_analysis': {'corrective_actions': 'Upgrade to fixed builds and '
                                                  'verify SAML configurations',
                            'root_causes': 'Memory overflow vulnerability in '
                                           'NetScaler ADC and NetScaler '
                                           'Gateway'},
 'recommendations': 'Prioritize patching based on version and SAML '
                    'configuration. Verify SAML configurations via CLI '
                    'commands (`add authentication samlAction` or `add '
                    'authentication samlIdPProfile`).',
 'references': [{'source': 'Citrix Security Bulletin', 'url': 'CTX697191'}],
 'response': {'communication_strategy': 'Public disclosure via security '
                                        'bulletin CTX697191',
              'containment_measures': 'Upgrade to fixed builds as per security '
                                      'bulletin CTX697191',
              'remediation_measures': 'Patch affected systems to the latest '
                                      'secure versions'},
 'stakeholder_advisories': 'Organizations using affected NetScaler ADC and '
                           'NetScaler Gateway versions must upgrade to fixed '
                           'builds.',
 'title': 'Critical Citrix NetScaler Vulnerability (CVE-2026-107406) Exposes '
          'Systems to RCE and DoS Risks',
 'type': 'Vulnerability Disclosure',
 'vulnerability_exploited': 'CVE-2026-107406 (Memory Overflow)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.