THEMETASEC

Cybersecurity News, Aggregated

Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway

CSO Online · 2 hours ago Vuln

For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution. This week’s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language) identity provider (IdP); older versions are also vulnerable when configured as a SAML service provider (SP), Citrix said in an advisory about the vulnerability, which it is tracking as CVE-2026-107406. Citrix rated the vulnerability critical, with a CVSS v4.0 score of 9.5. It said it was “not aware of any unmitigated exploits of this vulnerability.” Nevertheless, it encouraged affected customers to upgrade to patched versions as soon as possible: 13.1-64.29 or later for the 13.1 series, and 14.1-73.46 or later for the 14.1 series of ADC and Gateway, and 13.1.37.283 or later for ADC 13.1-FIPS.  Or 13.1-NDcPP. Citrix’s recent run of bad news began on Sept. 27, a Sunday, when it advised users of NetScaler ADC and Gateway to take their systems offline and patch two critical unauthenticated remote code execution vulnerabilities immediately as they were both under active attack, prompting one security researcher to warn, “Monday will be too late.” More flaws turned up last week including another memory overflow vulnerability (CVE-2026-88779), this one rated 8.7 on the CVSS 4.0 scale. Citrix said it was being actively exploited to cause denial of service. Citrix also released a new version of NetScaler ADC and Gateway, 14.1-60.58, that week, patching a critical memory overread vulnerability previously reported as CVE-2026-3055. Whether it’s memory overflows or memory overreads, when it comes to fixing security vulnerabilities in its NetScaler products Citrix seems to have a memory problem. This article first appeared on Network World.

Read full story at CSO Online →