Citrix disclosed CVE-2026-107406, a critical memory-overflow vulnerability in NetScaler ADC and NetScaler Gateway with a CVSS v4.0 score of 9.5. Successful exploitation could cause remote code execution or denial of service, depending on the appliance build and SAML identity-provider or service-provider configuration. Advisory CTX697191 also covers affected appliances used in Secure Private Access Hybrid deployments. Citrix stated that it was not aware of any unmitigated exploits at publication; Beazley Security Labs reported no known public proof of concept or independent technical analysis.
Administrators should verify appliance versions and SAML configurations, then upgrade to the applicable fixed release, including 14.1-73.46 or 13.1-64.29 for standard editions, with separate fixes for FIPS editions. Citrix has not published a workaround; temporary exposure reductions and monitoring can supplement, but not replace, patching. Recent exploitation of three other NetScaler vulnerabilities, including a separate SAML-processing flaw, heightens the urgency. Security teams should investigate suspicious activity on previously exposed appliances, because installing a fix does not establish whether an earlier compromise occurred.

Map this exposure pattern across your cloud, code, and identities.
9 events from the most recent confirmed update back to the earliest known activity.
Citrix published bulletin CTX697191 for a CVSS v4.0 9.5 memory-overflow vulnerability that could allow remote code execution or denial of service in NetScaler ADC and Gateway, depending on software build and SAML configuration. Citrix stated that it was not aware of any unmitigated exploits at publication.
CISA added the exploited NetScaler SAML-processing vulnerability CVE-2026-88779 to its Known Exploited Vulnerabilities catalog.
CISA added both NetScaler vulnerabilities to its Known Exploited Vulnerabilities catalog following their exploitation as zero-days.
Citrix disclosed eight NetScaler vulnerabilities, including the previously exploited CVE-2026-88771 and CVE-2026-88772.
watchTowr reported that exploitation of earlier NetScaler vulnerabilities compromised multiple government agencies and large enterprises, resulting in bulk theft of credentials and secrets. It urged patched organizations to investigate historical compromise and organizations with unpatched internet-facing appliances to assume compromise and begin triage.
Researchers and administrators reported that NetScaler vulnerability CVE-2026-88779 could also enable remote code execution. The flaw had previously been described as allowing denial-of-service attacks that crash authentication services and force appliance reboots.
Citrix released fixes for supported NetScaler branches and urged affected customers to upgrade to the applicable releases, including 14.1-73.46 and 13.1-64.29 for standard editions and separate FIPS/NDcPP builds. Its published guidance did not provide a workaround.
Attackers exploited a memory-overflow vulnerability in NetScaler SAML processing to crash authentication services and force appliance reboots. The flaw affects appliances configured as a SAML service provider or identity provider.
Attackers exploited CVE-2026-88771, an unauthenticated command-execution vulnerability, and CVE-2026-88772, a memory-overflow vulnerability affecting appliances with DTLS enabled, before disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
17 references tracked. Mallory keeps watching after this page renders.
socprime.com
Open sourcecyber.gc.ca
Open sourcetheregister.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcebankinfosecurity.com
Open sourcelabs.beazley.security
Open sourcecommunity.citrix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.