Citrix NetScaler: a 9.5-severity memory overflow demands immediate patching

Citrix patches CVE-2026-107406, a CVSS 9.5 NetScaler memory overflow enabling RCE or DoS. What K-12 and government admins must do now.

  • Citrix released patches for CVE-2026-107406, a CVSS 9.5 memory overflow in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service.
  • SAML deployments are specifically called out; internet-facing appliances are the priority, and Citrix is urging immediate patching.
  • No confirmed exploitation yet, but affected versions and exact trigger conditions are not fully public — verify with the vendor advisory.

What to do now

  1. Inventory every NetScaler ADC and NetScaler Gateway instance — physical, virtual, disaster-recovery and lab — and record version, internet exposure and whether SAML is configured.
  2. Apply the Citrix update for CVE-2026-107406 immediately, starting with internet-facing appliances; schedule emergency maintenance if required.
  3. If patching cannot happen now, disable SAML or restrict management and authentication interfaces to trusted networks, and enforce MFA for all administrative access.
  4. Review NetScaler and identity-provider logs for service crashes, memory-related errors, anomalous SAML assertions and unexpected outbound connections; preserve evidence.
  5. After patching, validate SAML authentication flows, re-scan the appliances to confirm the fix, and document completion for audit and incident-response records.

Related items