FR
live
tag

#citrix

Citrix urges patching a NetScaler RCE flaw that hits SAML-configured appliances

On October 9, 2026, Citrix shipped a fix for CVE-2026-107406, a memory-overflow bug that lets an attacker run code remotely or crash NetScaler ADC and Gateway appliances configured as a SAML identity provider or service provider. Upgrade to 14.1-73.46 or 13.1-64.29, or drop the SAML configuration if you do not use it.

CVE-2026-8452, patched in June as a DoS, is an exploited pre-auth RCE on Citrix NetScaler

On 30 June 2026, Citrix rated CVE-2026-8452 as a memory overflow. On 14 August, WatchTowr showed it leads to pre-authentication code execution, and on 26 August CISA added it to the KEV catalog with a 29 August deadline. Appliances configured as VPN or AAA servers must be patched today, without waiting for official confirmation of exploitation.

Citrix NetScaler patches a critical remote authentication bypass (CVSS 9.3) exploitable without credentials

On August 19, 2026, Cloud Software Group published a bulletin for NetScaler ADC and NetScaler Gateway: CVE-2026-19490, a CVSS 9.3 authentication bypass exploitable remotely without credentials, and CVE-2026-19489, an 8.8 denial-of-service. Any internet-facing appliance needs an emergency upgrade, after triage driven by the SAML or vserver configuration.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss