Citrix urges updates for NetScaler login-system flaw
Source announcement: 8 October 2026
Event date: The flaw was disclosed on 8 October 2026
Citrix has urged customers to update affected NetScaler ADC and NetScaler Gateway appliances after disclosing CVE-2026-107406. These products can sit at the entrance to business applications and remote-access services. Citrix says a memory-handling flaw could allow remote code execution—running an attacker’s commands—or cause the appliance to stop working.
The risk depends on configuration as well as version. The appliance must be set up for SAML, a system that passes login information between services. Older listed releases can be affected when acting as either a SAML service provider or identity provider. Some newer listed releases are affected only when acting as an identity provider. This is a warning for organisations operating customer-managed appliances, including some Secure Private Access Hybrid deployments; Citrix says it is updating the relevant Citrix-managed cloud services itself.
A successful attack could interrupt staff access or put business systems behind the gateway at risk. The public bulletin describes what the weakness could allow, but does not establish that every exposed appliance has been compromised. It also does not give readers a way to diagnose an intrusion from a failed login alone.
Citrix recommends 14.1-73.46 or later, 13.1-64.29 or later, with separate fixed releases for FIPS and NDcPP editions. Administrators should check both their software version and SAML role against the bulletin, then schedule the appropriate update promptly. If a supplier manages the gateway, ask it to confirm those checks and the installed release.








Comments