{"id":9966,"date":"2026-10-09T14:28:21","date_gmt":"2026-10-09T14:28:21","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9966"},"modified":"2026-10-09T14:28:21","modified_gmt":"2026-10-09T14:28:21","slug":"citrix-issues-its-weekly-critical-security-patch-for-netscaler-adc-and-netscaler-gateway","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9966","title":{"rendered":"Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution.<\/p>\n<p class=\"wp-block-paragraph\">This week\u2019s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language) identity provider (IdP); older versions are also vulnerable when configured as a SAML service provider (SP), Citrix said in an <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX697191&amp;articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_107406\" target=\"_blank\" rel=\"noopener\">advisory about the vulnerability<\/a>, which it is tracking as <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-107406\" target=\"_blank\" rel=\"noopener\">CVE-2026-107406<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Citrix rated the vulnerability critical, with a CVSS v4.0 score of 9.5. It said it was \u201cnot aware of any unmitigated exploits of this vulnerability.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Nevertheless, it encouraged affected customers to upgrade to patched versions as soon as possible: 13.1-64.29 or later for the 13.1 series, and 14.1-73.46 or later for the 14.1 series of ADC and Gateway, and 13.1.37.283 or later for ADC 13.1-FIPS.\u00a0 Or 13.1-NDcPP.<\/p>\n<p class=\"wp-block-paragraph\">Citrix\u2019s recent run of bad news began on Sept. 27, a Sunday, when it advised users of NetScaler ADC and Gateway to take their systems offline and patch two critical unauthenticated remote code execution vulnerabilities immediately as they were both under active attack, prompting one security researcher to warn, \u201c<a href=\"https:\/\/www.networkworld.com\/article\/4227476\/netscaler-admins-told-to-patch-critical-zero-days-in-adc-and-gateway-now.html\">Monday will be too late<\/a>.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.csoonline.com\/article\/4230642\/citrix-warns-of-actively-exploited-netscaler-flaw-days-after-zero-day-patch-rush.html\">More flaws turned up last week<\/a> including another memory overflow vulnerability (<a href=\"http:\/\/cve.org\/CVERecord?id=CVE-2026-88779\" target=\"_blank\" rel=\"noopener\">CVE-2026-88779<\/a>), this one rated 8.7 on the CVSS 4.0 scale. Citrix said it was being actively exploited to cause denial of service. Citrix also released a new version of NetScaler ADC and Gateway, 14.1-60.58, that week, patching a critical memory overread vulnerability previously reported as <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3055\">CVE-2026-3055<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Whether it\u2019s memory overflows or memory overreads, when it comes to fixing security vulnerabilities in its NetScaler products Citrix seems to have a memory problem.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <a href=\"https:\/\/www.networkworld.com\/article\/4233186\/citrix-issues-its-weekly-critical-security-patch-for-netscaler-adc-and-netscaler-gateway.html\">Network World<\/a>.<\/em><\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution. This week\u2019s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language) [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9967,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9966","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9966"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9966"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9966\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9967"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9966"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}