# Citrix urges NetScaler patching for critical remote code execution flaw

_Published Friday, October 9, 2026 at 4:58 AM EDT · Security · Latest · Tier 2 — Notable_

![Citrix urges NetScaler patching for critical remote code execution flaw — Primary](https://www.bleepstatic.com/content/hl-images/2026/10/09/Citrix.jpg)

Citrix urged administrators to patch a critical vulnerability that can let attackers execute code remotely or crash NetScaler ADC and NetScaler Gateway appliances. The memory overflow flaw, CVE-2026-107406, affects appliances configured to act as an identity provider or service provider using Security Assertion Markup Language, a protocol for exchanging authentication information.

Citrix recommends upgrading to fixed versions, including 14.1-73.46 or later and 13.1-64.29 or later releases of 13.1, with separate updates for FIPS and NDcPP editions. The company said it had found no evidence of exploitation in the wild. Internet exposure counts do not establish how many devices have vulnerable configurations or remain unpatched.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-patch-new-netscaler-rce-flaw-immediately/)

---
Canonical: https://techandbusiness.org/newswire/3CGn186yn9ufKsHPpzVboN
Published: 2026-10-09T08:58:20.161Z
Story chronology: 2026-10-09T08:27:42.000Z
Retrieved: 2026-10-09T10:54:27.503Z
Publisher: Tech & Business (techandbusiness.org)
