BREACH WATCH BRIEF Critical 🐛 Vulnerability

Critical Remote Code Execution Vulnerability (CVE‑2026‑107406) in Citrix NetScaler ADC & Gateway

Citrix disclosed CVE‑2026‑107406, a memory‑overflow RCE flaw affecting NetScaler ADC and Gateway when used as SAML IdP/SP. The vulnerability underscores the need for continuous patch management and audit‑ready evidence of remediation.

SeverityCritical
Type🐛 Vulnerability
ConfidenceHigh
ReportedOct 9, 2026
Cloud & Infrastructure Providers Enterprises running Citrix NetScaler ADC or Gateway for remote access, load balancing, or SAML federation. Vulnerability Exploit

What happened

Citrix announced CVE‑2026‑107406, a critical memory‑overflow vulnerability that enables unauthenticated remote code execution or denial‑of‑service on NetScaler ADC and Gateway appliances configured as SAML IdP or SP. No active exploits have been observed, but the vendor urges immediate patching to the latest releases.

Why it matters for trust and compliance

  • The flaw illustrates why organizations must maintain a continuous vulnerability‑management control that captures, prioritises, and documents remediation actions, providing defensible evidence for audits across frameworks.
  • Enables continuous monitoring of patch status as evidence of control effectiveness.
  • Supports audit‑ready documentation of remediation actions for multiple compliance frameworks.

Who is affected

Enterprises running Citrix NetScaler ADC or Gateway for remote access, load balancing, or SAML federation.

Recommended actions

  1. Inventory all NetScaler instances and flag those acting as SAML IdP/SP.
  2. Apply the vendor‑recommended patches (14.1‑73.46+, 13.1‑64.29+, etc.) without delay.
  3. Record patch installation details in your configuration‑management database for audit trails.
  4. Enable IDS/EDR signatures for CVE‑2026‑107406 and monitor for any exploitation attempts.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.