Citrix gives NetScaler admins another critical reason to patch
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration. Citrix's advisory lists the affected builds and required updates. Secure Private Access Hybrid deployments using NetScaler instances also need patching. Citrix classifies the flaw as CWE-119: improper restriction of operations within a memory buffer. Customers must update their own deployments. Citrix says it handles the necessary updates for its managed cloud services and Adaptive Authentication. …
You're reading a preview. The full article is published by The Register on their website.
Read the full story on The Register

