Citrix has released patches for CVE-2026-107406, a critical vulnerability in NetScaler ADC and NetScaler Gateway that can lead to remote code execution or denial of service. The flaw, a memory overflow issue (CWE-119), carries a CVSS v4.0 score of 9.5. It affects deployments configured as a SAML service provider or identity provider, depending on the build; newer builds are only vulnerable in the identity provider configuration.

All four sources agree the patch should be applied immediately. There is a slight discrepancy on exploitation status: The Register notes Citrix did not say whether the flaw had been exploited before disclosure, while The Hacker News states there is no evidence of in-the-wild exploitation. Citrix credited researchers from JPMorgan Chase's XOR Team and Maxim Suhanov for the discovery.

The advisory also covers Secure Private Access Hybrid deployments using NetScaler instances. Citrix says it will handle updates for managed cloud services and Adaptive Authentication, but customers must patch their own deployments. The disclosure follows a string of NetScaler vulnerabilities already under active attack, including CVE-2026-88772 and CVE-2026-88779, making this latest advisory part of a broader patch cycle.