
Citrix urges customers to apply a patch for another critical NetScaler vulnerability following weeks of disclosures about actively exploited issues. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution or denial of service. It has been assigned a score of 9.5 on the CVSS v4.0 scale.
Affected configurations depend on the software version. Older builds are vulnerable if configured as a SAML service provider or as an identity provider (IdP); some newer builds are vulnerable only in the IdP configuration. Citrix's advisories list the affected builds and necessary updates. The patch is also required for Secure Private Access Hybrid deployments using NetScaler instances. Citrix classifies the issue as CWE-119 – Improper Restriction of Operations within the Bounds of a Memory Buffer. Customers must update their deployments themselves. For managed cloud services and Adaptive Authentication, Citrix performs the necessary updates.
Citrix did not specify whether this vulnerability was exploited as a zero-day before disclosure, but credited Michael Tucker, Chiu Keong Tan, and Alex Bernier from the XOR JPMorgan Chase team, as well as Maxim Sukhanov, for discovering it. According to Google researchers, the campaign exploiting CVE-2026-88772 has been ongoing since at least early September; it likely affects organizations in government, finance, legal, and education sectors in North America and Europe. Citrix disclosed this vulnerability weeks later as part of a release addressing eight vulnerabilities. Last Friday, Citrix disclosed another exploitable vulnerability – CVE-2026-88779 with a severity index of 8.7. Both it and the new vulnerability are related to memory overflow affecting SAML configurations. The new one also allows remote code execution, has a higher score, and is not identified by Citrix as being exploited.
This material is prepared solely for informational purposes and does not constitute financial advice or a recommendation.
