Citrix Urges Immediate Patching of Critical NetScaler RCE Flaw
Citrix has issued an urgent warning to IT administrators to patch a critical vulnerability in NetScaler ADC networking appliances and NetScaler Gateway remote access solutions. The flaw, identified as CVE-2026-107406, is a memory overflow weakness that can be exploited for remote code execution or to cause denial-of-service crashes. The vulnerability affects appliances configured as SAML Identity Provider or Service Provider. Citrix has provided specific upgrade paths for affected versions and emphasized the importance of immediate action, though no exploits have been observed yet. The company also highlighted several other NetScaler vulnerabilities that have been actively exploited this year, including issues leading to web shell deployment, credential theft, and network infiltration.
Read the full article
Continue reading at BleepingComputer →This is an AI-generated summary. Read the original for the full story.