[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fS_us5jtRfjkZLNtcCkJbi2G8Tz_AcEO9JejP3Be79Gs":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"d9bc5624-7f2b-48bd-9de0-dcaf76c21dbf","Citrix warns admins to patch new NetScaler RCE flaw immediately","citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately-0c103a","Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. [...]","Citrix has issued an urgent warning for IT administrators to patch a critical remote code execution (RCE) vulnerability, CVE-2026-107406, affecting NetScaler ADC and NetScaler Gateway appliances. The flaw, a memory overflow weakness, can lead to RCE or denial-of-service crashes when the appliances are configured as SAML IdP or SP. While Citrix is unaware of active exploitation, the company highlights a history of previously disclosed NetScaler vulnerabilities being abused by threat actors.","Citrix warns of critical NetScaler RCE flaw, CVE-2026-107406, urging immediate patching.","Citrix warns admins to patch new NetScaler RCE flaw immediately By Sergiu Gatlan October 9, 2026 04:27 AM 0 Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. Tracked as CVE-2026-107406, this flaw stems from a memory overflow weakness that attackers can exploit to gain remote code execution (RCE) on targeted devices or trigger a denial-of-service state that can cause crashes. To be vulnerable, NetScaler ADC and NetScaler Gateway appliances must be configured as a Security Assertion Markup Language (SAML) Identity Provider (IdP) or Service Provider (SP). \"We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible,\" the company said. \"As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.\" Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to: NetScaler ADC and NetScaler Gateway 14.1-73.46 and later, NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases of 13.1 NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS and later releases of 14.1-FIPS NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1.37.283 and later releases of 13.1-FIPS and 13.1-NDcPP Internet threat watchdog Shadowserver tracks over 21,000 IP addresses with NetScaler fingerprints exposed on the Internet (including just over 1,500 Gateway instances and nearly 20,000 NetScaler ADC appliances). However, at the time, there is no information on how many are honeypots, have already been patched, or have vulnerable configurations. Internet-exposed NetScaler appliances (Shadowserver) While Citrix has not found evidence that attackers have begun exploiting CVE-2026-107406 in the wild, the company warned of several other NetScaler vulnerabilities that attackers have abused since the start of the year. For instance, in March, Citrix urged customers to patch two other NetScaler security issues (CVE-2026-3055 and CVE-2026-4368) days before threat actors began abusing them. More recently, in September, it released security updates for two more actively exploited NetScaler RCE zero-days (CVE-2026-88771 and CVE-2026-88772) that let attackers deploy custom web shells and tunneling malware, steal credentials, gain root access, and spread into victims' internal networks. Earlier this month, Citrix issued emergency updates to address a NetScaler denial-of-service zero-day flaw (CVE-2026-88779) that researchers and admins later said could also be exploited to gain remote code execution. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged 27 actively exploited Citrix vulnerabilities since November 2021, including seven abused in ransomware attacks. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: CISA orders feds to patch exploited Citrix flaws by WednesdayCitrix urges admins to patch new NetScaler flaws as soon as possibleCisco warns of critical flaws allowing Nexus switch takeoverCritical Cisco bug lets hackers add root users on SEG devicesCISA orders feds to patch Citrix NetScaler RCE flaw by Saturday","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcitrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F10\u002F09\u002FCitrix.jpg","2026-10-09T08:27:42+00:00","2026-10-09T10:00:36.995069+00:00",9,[18,21,23,26],{"name":19,"type":20},"NetScaler ADC","product",{"name":22,"type":20},"NetScaler Gateway",{"name":24,"type":25},"Citrix","vendor",{"name":27,"type":28},"SAML","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,37,42],{"category":36},{"id":29,"icon":31,"name":32,"slug":33},{"category":38},{"id":39,"icon":31,"name":40,"slug":41},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,52,55,57,60,62],{"type":49,"value":50,"context":51},"cve","CVE-2026-107406","Critical RCE and DoS vulnerability in NetScaler ADC and Gateway.",{"type":49,"value":53,"context":54},"CVE-2026-3055","Previously disclosed NetScaler vulnerability.",{"type":49,"value":56,"context":54},"CVE-2026-4368",{"type":49,"value":58,"context":59},"CVE-2026-88771","Actively exploited NetScaler RCE zero-day.",{"type":49,"value":61,"context":59},"CVE-2026-88772",{"type":49,"value":63,"context":64},"CVE-2026-88779","NetScaler denial-of-service zero-day, potentially RCE."]