Critical [CVE-2026-107406] Protecting Customers: Immediate Guidance for CVE-2026-107406 in NetScaler ADC and NetScaler Gateway
This critical-severity NetScaler (Citrix) advisory covers CVE-2026-107406 affecting Gateway.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future NetScaler (Citrix) CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Today, Citrix published a critical security bulletin for NetScaler ADC and NetScaler Gateway regarding CVE-2026-107406. CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial of service under specific configuration conditions.
The issue carries a CVSS v4.0 base score of 9.5 and is rated Critical. We strongly urge affected customers to review the advisory and upgrade impacted NetScaler instances to the recommended versions as soon as possible.
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
- NetScaler ADC and NetScaler Gateway before 14.1-73.37
- NetScaler ADC 14.1-FIPS before 14.1-73.37
- NetScaler ADC and NetScaler Gateway before 13.1-64.23
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
- 14.1-73.37
- 13.1-64.23
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Mitigation checklist
- Upgrade to a fixed build: 14.1-73.37, 13.1-64.23 or later for your release line.
Official advisory · high-confidence parse· fetched 1 day ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.