Citrix NetScaler ADC and NetScaler Gateway memory overflow denial-of-service flaw (CVE-2026-107406)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-107406 is a critical memory overflow in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial-of-service in specific SAML SP/SAML IdP configurations. Citrix says the flaw also affects Secure Private Access Hybrid deployments that use NetScaler. Fixed builds are available, and customers are being told to upgrade immediately. Citrix said it was not aware of any unmitigated exploits at publication.
Related Happenings
NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)
Vulnerability
H score36
First: 05.10.2026 00:58
Last: 05.10.2026 00:58
Sources 1
About this happening:
Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SA...
NetScaler ADC and NetScaler Gateway memory buffer flaw (CVE-2026-88779, actively exploited)
VulnerabilityAbout this happening: Citrix disclosed CVE-2026-88779, a memory buffer flaw in NetScaler ADC and NetScaler Gateway that is being used in zero-day attacks. The issue affects SA...
WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances
Malware Activity
H score34
First: 30.09.2026 11:24
Last: 30.09.2026 11:24
Sources 1
About this happening:
A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance...
WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances
Malware ActivityAbout this happening: A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance...
Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)
Vulnerability
H score43
First: 28.09.2026 09:24
Last: 28.09.2026 09:24
Sources 1
About this happening:
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are under active exploitation against unmitigated NetScaler deployments, enabling unauthenticated remote c...
Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)
VulnerabilityAbout this happening: Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are under active exploitation against unmitigated NetScaler deployments, enabling unauthenticated remote c...
Latest development: 29.09.2026 21:37
Mandiant says attackers exploited Citrix NetScaler CVE-2026-88772 and CVE-2026-88771 to install the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneling tool, maintain root-level access, pivot into internal hosts, and steal credentials. The activity affected organizations in North America and Europe across government, financial services, education, legal, and professional services environments.
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/Mitigation
H score54
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler urgent patch guidance for CVE-2026-19490
Advisory/MitigationAbout this happening: Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, a CVSS 9.3 authentication-bypass flaw...
Citrix NetScaler authentication bypass (CVE-2026-19490)
Vulnerability
H score29
First: 04.09.2026 18:25
Last: 04.09.2026 18:25
Sources 1
About this happening:
CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Citrix NetScaler authentication bypass (CVE-2026-19490)
VulnerabilityAbout this happening: CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observe...
Timeline
-
09.10.2026 09:53 3 articles · 2h ago
Citrix warns of critical NetScaler memory overflow and urges immediate patching
Initial DisclosureCitrix warned that CVE-2026-107406 is a critical-severity NetScaler memory overflow that can lead to remote code execution or denial-of-service on NetScaler ADC and NetScaler Gateway appliances configured as a SAML SP or SAML IdP. The company also said Secure Private Access Hybrid deployments that use NetScaler are affected, that it was not aware of any unmitigated exploits at publication, and that fixed releases are available in versions 14.1-73.46, 13.1-64.29, 14.1-73.46 FIPS, and 13.1.37.283.
Show sources
- Citrix Urges Immediate Patching of Critical NetScaler Vulnerability — www.securityweek.com — 09.10.2026 09:53
- Citrix Urges Immediate Patching of Critical NetScaler Vulnerability — www.securityweek.com — 09.10.2026 09:53
- Citrix warns admins to patch new NetScaler RCE flaw immediately — www.bleepingcomputer.com — 09.10.2026 11:27