Critical Remote Code Execution Vulnerability in Citrix NetScaler
CVE-2026-107406 could allow remote code execution or denial of service on vulnerable NetScaler deployments configured for SAML authentication.
Summary
CVE-2026-107406 could allow remote code execution or denial of service on vulnerable NetScaler deployments configured for SAML authentication.
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability.
Threat details
End of life (EoL) products likely still vulnerable
NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End of Life (EoL) and are likely vulnerable. Organisations using EoL versions must upgrade to the latest release of supported versions as soon as possible.
Introduction
Citrix has released a security bulletin to address a critical vulnerability in NetScaler ADC and NetScaler Gateway. Successful exploitation could enable a remote attacker to execute arbitrary code or cause denial of service on vulnerable appliances configured for SAML authentication.
- CVE-2026-107406 - Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability - CVSSv4.0 Base Score: 9.5
CVE-2026-107406 will likely be exploited
Multiple remote code execution vulnerabilities have recently been disclosed in Citrix NetScaler appliances (CC-4858, CC-4834, CC-4832), and these vulnerabilities have received significant attention from security researchers and cyber criminals. Researchers have reported mass exploitation of recent NetScaler vulnerabilities within hours of a proof-of-concept exploit becoming publicly available, and the NHS England National CSOC assesses it is likely CVE-2026-107406 will be exploited.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Remediation advice
Affected organisations must review Citrix advisory CTX697191 and follow the remediation steps below.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Update to the latest fixed version Fixed versions include:
Note: NetScaler releases 12.1 and 13.0 are end-of-life and do not receive security updates. Organisations running end-of-life versions must migrate to a supported release.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697191 |
Definitive source of threat updates
Last edited: 9 October 2026 12:00 pm