Skip to the stories
Saturday, 10 October 2026
Saved

Next edition

5:53

Headlines

Bugs and Patches

Citrix issues emergency patch for critical NetScaler vulnerability

Citrix has released an emergency fix for a new critical memory overflow weakness in NetScaler appliances.

FTMQ Security, written by our newsroom0 views

Share

Citrix has issued emergency security updates to fix a new critical flaw affecting NetScaler ADC networking appliances and NetScaler Gateway remote access tools, BleepingComputer reported. BankInfoSecurity, The Register, and SecNews.gr also report that Citrix released emergency fixes for the security flaw. BleepingComputer reported that Citrix urged system administrators to apply the patch immediately. [1][2][3][4]

The vulnerability is tracked as CVE-2026-107406, according to BleepingComputer. The security weakness is caused by a memory overflow issue. BleepingComputer reported that hackers can exploit this flaw to execute remote code on affected devices or cause a denial of service. [4]

NetScaler was originally developed in 1997 and acquired by Citrix Systems in 2005. Citrix consolidated its networking tools under the NetScaler brand in 2016. NetScaler later became a business unit under Cloud Software Group in September 2022. [8]

As FTMQ Security reported earlier, Citrix issued emergency updates earlier in October 2026 for a separate zero-day memory overflow vulnerability tracked as CVE-2026-88779. That earlier flaw caused a denial of service in appliances using SAML authentication with Gateway and was under active exploitation. [9][10]

Share

In short

  • Citrix released emergency patches for NetScaler ADC and NetScaler Gateway devices.
  • The new flaw is tracked as CVE-2026-107406.
  • CVE-2026-107406 stems from a memory overflow weakness that allows remote code execution or denial of service.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Citrix Ships Another Emergency Fix for NetScaler AppliancesBankInfoSecurity, 8h ago (the report this story comes from)
  2. [2]Citrix gives NetScaler admins another critical reason to patchThe Register, 14h ago
  3. [3]Citrix patches critical NetScaler RCE vulnerabilitySecNews.gr, 14h ago
  4. [4]Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer, 18h ago
  5. [5]Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer, 18h ago
  6. [6]Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer, 18h ago
  7. [7]Citrix warns admins to patch new NetScaler RCE flaw immediatelyBleepingComputer, 18h ago

Background

  1. [8]NetScaler on Wikipedia
  2. [9]Citrix issues patches for NetScaler memory overflow flaw under active attack FTMQ Security, 4d ago
  3. [10]Citrix issues emergency updates for NetScaler zero day vulnerability FTMQ Security, 5d ago

Our newsroom writes these reports with the help of software, from the 10 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Bugs and Patches

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.