TL;DR: Citrix is telling NetScaler customers to drop what they are doing and patch. A new flaw rated 9.5 out of 10 can crash a gateway or hand an attacker control.
What Happened?
Citrix published a bulletin on a critical flaw in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406. It is a memory overflow that, under the right conditions, can lead to remote code execution or a denial of service that knocks the appliance offline.
The catch is the configuration. The flaw affects appliances set up as a SAML service provider or identity provider, as well as Secure Private Access Hybrid deployments on NetScaler. Citrix says it has no reports of active exploits yet.
What’s the Impact?
A NetScaler gateway is the front door to internal apps, and SAML is how users prove who they are. Take over that box and an attacker is past the perimeter and inside the login flow. Crash it instead, and remote workers lose access. Either way, the business stops.
How to Avoid This
There are no published indicators for this flaw yet, so act on the configuration and the patch, not a blocklist.
- Patch to a fixed build now: 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, or 13.1-37.283 for the FIPS and NDcPP lines.
- Find every NetScaler ADC and Gateway you run, including Secure Private Access Hybrid setups, because the one you forgot is the one that is exposed.
- Check which appliances are configured as a SAML SP or IdP, since those are the ones in scope.
- After patching, watch the box for odd behavior: unexpected reboots, memory spikes, crash loops, or new processes.
- Treat internet-facing appliances as a standing target and recheck them every time a bulletin lands, not once a quarter.
Before the next bulletin catches you off guard
A NetScaler vulnerability is an exposure problem before it is a patching problem. The appliance is reachable; the clock starts the moment the flaw goes public, and the one you missed gets hit.
- See every internet-facing appliance the way an attacker does, so nothing sits forgotten at the edge.
- Validate which exposures are reachable and misconfigured, so you fix the real risk first.
- Turn each finding into a patch with a clear owner, then retest to confirm the box is closed.
- Keep a record of what was exposed, what was patched, and who signed off, ready for the auditor or the board.
- Run it on a loop, because the next bulletin is already coming. Attack. Harden. Prove. Repeat.