Cybersecurity

Citrix Warns of Remote Command Execution Vulnerability in NetScaler and Urges Immediate Updates

Citrix warned of a critical vulnerability in NetScaler ADC appliances and NetScaler Gateway solutions that could allow remote command execution or cause a denial-of-service condition. The vulnerability affects appliances configured as SAML identity providers, while the company recommends upgrading to specific versions without waiting for confirmed exploitation.

2026-10-09
3 min read
5 views
certi.news Editorial Team
Citrix Warns of Remote Command Execution Vulnerability in NetScaler and Urges Immediate Updates

Citrix warned IT administrators about a critical vulnerability identified as CVE-2026-107406 in NetScaler ADC appliances and NetScaler Gateway solutions for secure remote access, and urged them to install the recommended updates immediately. The issue stems from a memory buffer overflow flaw that could be exploited to execute commands remotely on the target appliance or cause a denial-of-service condition that results in its failure.

Not all NetScaler deployments are necessarily vulnerable, as exploitation requires the appliance to be configured to operate as an identity provider or service provider within the Security Assertion Markup Language (SAML) protocol. Citrix said that, as of the publication of its security bulletin, it had no evidence of unremediated exploitation of the vulnerability in real-world attacks, but urged affected customers to review the bulletin and upgrade their systems as soon as possible.

Versions Recommended by Citrix

The company identified the following versions, or later versions, as addressing the issue:

  • NetScaler ADC and NetScaler Gateway 14.1-73.46 and later versions.
  • NetScaler ADC and NetScaler Gateway 13.1-64.29 and later releases in the 13.1 branch.
  • NetScaler ADC 14.1-FIPS version 14.1-73.46 FIPS and later versions in the 14.1-FIPS branch.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP version 13.1.37.283 and later releases in both branches.

Why Does This Warning Matter?

Shadowserver is monitoring more than 21,000 IP addresses exposing NetScaler fingerprints on the internet, including slightly more than 1,500 Gateway instances and approximately 20,000 NetScaler ADC appliances. This figure does not indicate how many of the appliances are actual exposed systems, honeypots, or systems that have been updated, nor does it prove that all of them use the SAML-related configuration, but it illustrates the potential size of the exposure surface.

The priority of applying the fix comes in the context of a recent history of NetScaler vulnerability exploitation. In March, Citrix urged customers to address two vulnerabilities identified as CVE-2026-3055 and CVE-2026-4368, days before attackers began exploiting them. In September, it issued updates for two zero-day remote command execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which were used to deploy web shells and tunneling malware, steal credentials, obtain root access, and move laterally within internal networks.

Earlier in the month, Citrix also issued emergency updates for a denial-of-service vulnerability identified as CVE-2026-88779, which researchers and system administrators later said could also be exploited for remote command execution. According to the source, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed 27 actively exploited vulnerabilities in Citrix products since November 2021, seven of which were associated with ransomware attacks.

In practice, NetScaler administrators need to first verify whether SAML settings are enabled, then match the version branch against Citrix's guidance and apply the appropriate update. The absence of confirmed exploitation of the current vulnerability does not mean that delaying is safe, particularly because previous vulnerabilities in the product progressed from warning to exploitation within a short period.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news