Citrix gives NetScaler admins another critical reason to patch
Citrix has warned customers to patch a critical vulnerability in NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial of service. The flaw has a CVSS v4.0 score of 9.5, although Citrix has not said whether attackers exploited it before disclosure.
The vulnerability, CVE-2026-107406, affects different software builds depending on whether NetScaler is configured as a SAML service provider or identity provider; Secure Private Access Hybrid deployments also need updates. Customers must patch systems they manage, while Citrix says it updates its managed cloud services and Adaptive Authentication. The alert follows recent disclosures of actively exploited Citrix flaws, including one tied to a campaign affecting organisations in several sectors across North America and Europe.
- Citrix urges customers to patch a NetScaler flaw rated 9.5.
- The vulnerability could enable remote code execution or denial of service.
- Citrix has not confirmed whether attackers exploited it before disclosure.
New here? Start with this
Citrix is a software company that makes tools used by businesses to manage remote access to their computer networks and applications. NetScaler is one of these tools—specifically, it controls which users can access what systems and handles security between internal networks and the internet.
A vulnerability is a flaw in software that attackers could potentially exploit to cause damage or steal information. When such a flaw is discovered, the software maker releases a patch, which is an update that fixes the problem. Organisations must install patches quickly to protect themselves.
This situation matters because NetScaler is used by many large organisations worldwide, meaning many companies could be affected by a flaw in it. Additionally, Citrix has faced multiple security issues recently, highlighting the importance of keeping such critical network access tools secure.