Citrix is urging IT administrators to patch NetScaler ADC and NetScaler Gateway appliances immediately after identifying a critical vulnerability that can allow remote code execution (RCE) and/or denial-of-service (DoS). The issue is tracked as CVE-2026-107406 and affects systems using NetScaler ADC networking functionality and NetScaler Gateway secure remote access.
According to multiple outlets, Citrix describes CVE-2026-107406 as a memory overflow vulnerability. Successful exploitation depends on specific configuration conditions, which can determine whether an attacker could execute code on the device or instead trigger a DoS outcome. One report highlights the risk in SAML deployments, suggesting the flaw’s impact may vary by how remote access and authentication features are set up.
The coverage aligns on the core guidance: administrators should apply Citrix’s released patches as soon as possible to reduce exposure. While outlets emphasize the same CVE and potential outcomes, they differ mainly in how they frame the exploitation context, including references to particular deployment scenarios.