Citrix warns of new critical NetScaler vulnerability
Organisations with SAML configurations should immediately check the latest patches and guidance, security agencies say.
Citrix has reported a new critical vulnerability in NetScaler ADC and NetScaler Gateway. Under specific SAML configurations, the flaw could allow remote code execution or a denial-of-service attack.
The vulnerability is designated CVE-2026-107406. According to Citrix, it is a memory overflow in NetScaler ADC and NetScaler Gateway. The risk applies to systems configured as a SAML service provider or SAML identity provider and meeting additional software-version conditions.
According to Citrix’s description, an attacker could exploit the flaw to execute code remotely or make a system unavailable. This does not mean that every NetScaler installation is vulnerable in the same way. The configuration, software version and enabled features are decisive.
The Australian Cyber Security Centre published a warning on Friday and calls the vulnerability critical. The agency stresses that earlier patches for other NetScaler problems do not fix this new flaw. Organisations should therefore recheck their current version and SAML setup.
The warning follows a series of NetScaler vulnerabilities about which security researchers and governments have already warned in recent weeks. The Australian Cyber Security Centre previously reported that at least two other vulnerabilities were actively exploited worldwide before a patch became available.
Citrix refers to specific firmware versions and configuration instructions for the solution. According to the company, organisations should update their systems and check for signs of exploitation. Those making NetScaler externally accessible should also determine whether log files show unusual activity and whether access credentials have been compromised.
The impact could be significant because NetScaler is often used as a gateway to corporate networks. A successful attack could affect remote access, identity verification and application availability. The article does not say that Dutch organisations have been affected; no public confirmation was found.
Security advisers recommend not delaying the patch until a regular maintenance cycle if an organisation meets the vulnerable conditions. At the same time, administrators should first establish which version and configuration are active, so that remediation measures are not applied incorrectly.
The main uncertainty is the extent of actual exploitation of this specific vulnerability. The Australian warning calls the vulnerability new and critical, but does not confirm concrete exploitation at Australian organisations. Citrix and governments will publish additional technical indicators as they become available.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The technical core and patching advice have been confirmed by Citrix and a national cybersecurity agency. The text clearly distinguishes between the new flaw and earlier NetScaler vulnerabilities.
- confirmed CVE-2026-107406 is a memory overflow in NetScaler ADC and NetScaler Gateway. — This is stated in Citrix’s security bulletin. source
- confirmed The flaw can lead to remote code execution or denial of service. — Citrix and the Australian Cyber Security Centre both describe these consequences. source
- confirmed The vulnerability concerns specific SAML configurations. — The Citrix description refers to SAML SP and IdP configurations. source
- confirmed Earlier patches do not fix this new vulnerability. — This is explicitly stated in the Australian Cyber Security Centre’s warning. source
- uncertain There is no public confirmation that Dutch organisations have been affected by this specific flaw. — This is a conclusion based on the public sources consulted, not proof that such incidents do not exist. source
Editor's note
The new vulnerability, the conditions for exposure and the patching advice have been confirmed by Citrix and the Australian Cyber Security Centre. No public confirmation was found that Dutch organisations have been affected by this specific flaw.Sources
More on this in Dutch media
- NU.nl — „citrix netscaler”
- De Telegraaf — „citrix netscaler”
- de Volkskrant — „citrix netscaler”