Find notable cyber news and cases, enriched with sources, timelines, and signals.

Citrix NetScaler ADC and NetScaler Gateway memory overflow denial-of-service flaw (CVE-2026-107406)

Vulnerability
First reported
Last updated
Happening score
H score 33
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-107406 is a critical memory overflow in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service in specific SAML SP/SAML IdP configurations. Citrix says the flaw also affects Secure Private Access Hybrid deployments that use NetScaler. Fixed builds are available, and customers are being told to upgrade immediately. Citrix said it was not aware of any unmitigated exploits at publication.

Related Happenings

NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)

Vulnerability
H score36 First: 05.10.2026 00:58 Last: 05.10.2026 00:58 Sources 1

About this happening: Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SA...

WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances

Malware Activity
H score34 First: 30.09.2026 11:24 Last: 30.09.2026 11:24 Sources 1

About this happening: A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance...

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability
H score43 First: 28.09.2026 09:24 Last: 28.09.2026 09:24 Sources 1

About this happening: Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are under active exploitation against unmitigated NetScaler deployments, enabling unauthenticated remote c...

Latest development: 29.09.2026 21:37

Mandiant says attackers exploited Citrix NetScaler CVE-2026-88772 and CVE-2026-88771 to install the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneling tool, maintain root-level access, pivot into internal hosts, and steal credentials. The activity affected organizations in North America and Europe across government, financial services, education, legal, and professional services environments.

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation
H score54 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability
H score29 First: 04.09.2026 18:25 Last: 04.09.2026 18:25 Sources 1

About this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...

Timeline

  1. 09.10.2026 09:53 3 articles · 2h ago

    Citrix warns of critical NetScaler memory overflow and urges immediate patching

    Initial Disclosure

    Citrix warned that CVE-2026-107406 is a critical-severity NetScaler memory overflow that can lead to remote code execution or denial-of-service on NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP or SAML IdP. The company also said Secure Private Access Hybrid deployments that use NetScaler are affected, that it was not aware of any unmitigated exploits at publication, and that fixed releases are available in versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283.

    Show sources