Citrix warns admins to patch NetScaler RCE flaw
🛡️ Citrix has urged administrators to immediately patch a critical memory overflow vulnerability (CVE-2026-107406) affecting NetScaler ADC and NetScaler Gateway when configured as a SAML IdP or SP. The flaw can enable remote code execution or cause denial-of-service conditions. Citrix provided targeted version updates and stressed rapid upgrades, noting no confirmed active exploitation at publication time. Shadowserver reports over 21,000 NetScaler fingerprints exposed online, underscoring the urgency.
