[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHMUGHYKOFF1pCiD4sEjnKzttWAYMChRB8_6gYWUzo8M":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"6072eac8-7440-4933-8a26-2eb822a2c12e","Citrix Urges Immediate Patching of Critical NetScaler Vulnerability","citrix-urges-immediate-patching-of-critical-netscaler-vulnerability-8d2528","The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service. The post Citrix Urges Immediate Patching of Critical NetScaler Vulnerability appeared first on SecurityWeek.","Citrix has issued a critical warning for a NetScaler vulnerability, CVE-2026-107406, with a CVSS score of 9.5. This memory overflow flaw can lead to remote code execution or denial-of-service and affects NetScaler ADC and Gateway appliances configured as SAML SP or IdP, as well as Secure Private Access Hybrid deployments. While Citrix is unaware of any active exploits, they urge immediate patching to the latest versions.","Citrix warns of critical NetScaler vulnerability (CVE-2026-107406) requiring immediate patching.","Citrix on Thursday warned users of a critical-severity NetScaler vulnerability that requires immediate patching. Tracked as CVE-2026-107406 (CVSS score of 9.5), the flaw is described as a memory overflow that could lead to remote code execution (RCE) or denial-of-service (DoS). According to Citrix, the security defect impacts NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP or SAML IdP, under specific configuration conditions. The bug also affects Secure Private Access Hybrid deployments that use NetScaler. Customers need to update these NetScaler instances as well. Patches were included in NetScaler ADC and Gateway versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283 (of 13.1-FIPS and 13.1-NDcPP). “As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability,” Citrix notes, urging customers to upgrade their instances as soon as possible.Advertisement. Scroll to continue reading. Citrix’s fresh warning comes days after the company sounded the alarm on CVE-2026-88779, a zero-day in NetScaler leading to DoS. A week before, two other NetScaler zero-days were patched: CVE-2026-88771 (leading to RCE), and CVE-2026-88772 (leading to RCE or DoS). They have been exploited in attacks against government, financial services, education, legal, and professional services organizations. Related: Critical NetScaler Vulnerability Exploited in Attacks Related: Cisco Patches a Dozen Critical Vulnerabilities Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication Related: SonicWall and Splunk Patch Critical Vulnerabilities Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Fake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeFortiBleed Attackers Locking Victims Out of Fortinet DevicesQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyChrome 155 Update Patches 247 VulnerabilitiesASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware Latest News Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC PublicationUS Seeks Alleged Chinese Hafnium Hacker With $10 Million RewardSonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at Runtime Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcitrix-urges-immediate-patching-of-critical-netscaler-vulnerability\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FCitrix-vulnerability.jpeg","2026-10-09T06:53:53+00:00","2026-10-09T08:00:05.770256+00:00",9,[18,21,23,26,29],{"name":19,"type":20},"NetScaler ADC","product",{"name":22,"type":20},"NetScaler Gateway",{"name":24,"type":25},"Citrix","vendor",{"name":27,"type":28},"SAML","technology",{"name":30,"type":20},"Secure Private Access Hybrid","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":31,"icon":33,"name":34,"slug":35},null,"Vulnerabilities","vulnerabilities",[37,42,44],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[50,54,57,59],{"type":51,"value":52,"context":53},"cve","CVE-2026-107406","Critical NetScaler vulnerability",{"type":51,"value":55,"context":56},"CVE-2026-88779","Previous NetScaler zero-day vulnerability",{"type":51,"value":58,"context":56},"CVE-2026-88771",{"type":51,"value":60,"context":56},"CVE-2026-88772"]