
UpTrajectory Review
Citrix has issued its third critical security advisory for NetScaler ADC and Gateway in as many weeks, this time flagging CVE-2026-107406, a memory overflow vulnerability that can enable denial of service or remote code execution. The flaw specifically affects ADC and Gateway instances configured as a SAML identity provider, with older versions also vulnerable when configured as a SAML service provider. Citrix rated it 9.5 on the CVSS 4.0 scale and says it has no evidence of unmitigated exploits in the wild. Patched versions are available for the 13.1 and 14.1 series, including a FIPS-compliant build for regulated environments.
If your business runs its own NetScaler appliances rather than relying on Citrix-managed cloud services, this is not a routine patch cycle. The Sept. 27 advisory involved vulnerabilities already under active attack, with a researcher warning that waiting until Monday would be too late. That kind of language is rare in vendor communications and should tell you something about the urgency. For small and mid-sized businesses without a dedicated security team, three critical advisories in three weeks means someone on your staff needs to be checking Citrix's advisory page weekly, if not daily, until this streak ends.
What stands out here is not just the frequency but the pattern. Memory overflow, memory overread, another memory overflow — these are not exotic attack vectors. They are the kind of flaws that suggest either a systemic code quality problem in the NetScaler codebase or a security review process that is only now catching issues that have existed for some time. Citrix's reassurance that no unmitigated exploits are known for this particular CVE is worth noting, but it is also the same kind of language vendors use before the next advisory drops.
The SAML angle deserves attention because it narrows the exposure in a useful way. If your NetScaler deployment is not acting as a SAML identity provider, this specific flaw may not affect you. But the Sept. 27 vulnerabilities were unauthenticated remote code execution with no such configuration requirement, and last week's CVE-2026-88779 was already being exploited for denial of service. The practical takeaway is that you cannot triage these advisories in isolation. Each one needs to be evaluated against your actual deployment, and if you have not documented which SAML roles your NetScaler instances perform, now is the time.
The downstream effects reach beyond your IT department. If your NetScaler Gateway handles remote employee access or your ADC fronts customer-facing applications, a compromise or outage has direct revenue and operational consequences. Businesses in regulated industries face additional exposure if they cannot demonstrate timely patch management. And if you rely on a managed service provider to maintain your NetScaler instances, this is the moment to confirm they are tracking these advisories and applying patches within days, not months.
Watch whether Citrix's advisory pace slows in the coming weeks or whether this becomes a rolling disclosure cycle. If your team has not yet patched for the Sept. 27 vulnerabilities, treat that as the priority and then work through the subsequent advisories in order of severity. If you are on an older NetScaler version that cannot be patched, isolate the appliance from internet-facing exposure where possible and begin planning an upgrade. Three critical advisories in three weeks is not a coincidence — it is a signal that the product's security posture is under sustained scrutiny, and your exposure window is only as narrow as your patch latency.
“Monday will be too late.” — CSO Online
Takeaway: If you self-manage NetScaler ADC or Gateway, assign someone to track Citrix advisories weekly and patch within days — three critical flaws in three weeks means patch latency is your biggest risk.
Excerpt from the original — CSO Online
For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution.
This week’s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language) identity provider (IdP); older versions are also vulnerable when configured as a SAML service provider (SP), Citrix said in an advisory about the vulnerability, which it is tracking as CVE-2026-107406.
Citrix rated the vulnerability critical, with a CVSS v4.0 score of 9.5. It said it was “not aware of any unmitigated exploits of this vulnerability.”
Nevertheless, it encouraged affected customers to upgrade to patched versions as soon as possible: 13.1-64.29 or later for the 13.1 series, and 14.1-73.46 or later …