By Divya
Publication Date: 2026-10-09 06:17:00
Citrix has disclosed a critical memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial of service under specific configuration conditions.
This vulnerability, tracked as CVE-2026-107406, carries a CVSS v4.0 base score of 9.5, prompting an urgent upgrade advisory for affected customer-managed deployments.
The security bulletin, CTX697191, identifies this weakness as CWE-119, which involves improper restriction of operations within the bounds of a memory buffer.
The severity vector indicates that exploitation requires no privileges or user interaction, although the attack complexity is high. Successful exploitation could compromise the confidentiality, integrity, and availability of vulnerable appliances.
Citrix stated that it was not aware of any unmitigated exploits when it published the bulletin. However, this does not eliminate the exposure for deployments that meet the affected software version and…

