Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway
Summary
Citrix has issued another critical security warning for NetScaler ADC and NetScaler Gateway, detailing a memory overflow vulnerability that could lead to denial of service or remote code execution. This is the third consecutive week Citrix has alerted customers to critical vulnerabilities in these products, with the latest one, CVE-2026-107406, rated at a CVSS v4.0 score of 9.5.
IFF Assessment
This article details critical vulnerabilities in widely used Citrix products, posing a significant risk to organizations that rely on them for identity and access management.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: April 02, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching Citrix NetScaler ADC and Gateway instances, especially those configured as SAML IdP or SP, to mitigate the risk of exploitation. The recurring nature of these critical vulnerabilities highlights the importance of continuous monitoring and rapid response to security advisories for critical infrastructure.