Jessica Entwistle
October 9 2026
Citrix has issued an urgent advisory calling for immediate patching of a critical vulnerability in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406. SecurityWeek reports that the flaw could allow remote code execution or denial of service on affected systems. Citrix has released patches and is urging organisations to apply them as a priority. NetScaler appliances are widely used across UK enterprises for application delivery, load balancing and secure remote access, making them a common target for attackers seeking initial access to corporate networks. The fact that Citrix has specifically urged immediate action suggests the vendor assesses the risk of exploitation as significant, and that organisations should treat this as a high-priority patching activity.
Critical vulnerabilities in internet-facing infrastructure such as NetScaler represent a high-priority risk because they are often exploited quickly once details become public, and because they can provide attackers with a foothold into internal networks, access to sensitive traffic or the ability to disrupt services. For organisations that rely on NetScaler for remote access or application delivery, a successful exploit could allow an attacker to execute code on the appliance, intercept or manipulate traffic, or cause a denial of service that disrupts business operations. NetScaler appliances are commonly deployed at the network edge, where they handle authentication, encryption and traffic routing for critical applications and remote users. This makes them an attractive target for attackers, and a successful compromise can have significant downstream impact. For many UK organisations, NetScaler appliances are managed by infrastructure or networking teams rather than security teams, which can sometimes mean patching cycles are slower than for other critical systems. This vulnerability is a reminder that network appliances require the same level of attention and urgency as servers and endpoints when critical patches are released.
UK organisations using Citrix NetScaler should confirm whether patches for CVE-2026-107406 have been applied, whether vulnerable systems are exposed to the internet, and whether monitoring is in place to detect exploitation attempts or unusual activity on NetScaler appliances. Consider whether responsibility for patching network appliances is clearly assigned, whether these systems are included in regular vulnerability management cycles, and whether there is a process for prioritising and applying critical patches outside of normal maintenance windows. Organisations should also consider whether they have visibility of all NetScaler deployments, including those that may be managed by different teams or business units, and whether configuration management and change control processes are in place to ensure patches are applied consistently. Where NetScaler appliances are used for remote access, consider whether alternative access methods or contingency plans are available in the event that systems need to be taken offline for emergency patching. This is also a prompt to review whether monitoring and logging are configured to detect signs of compromise or exploitation, and whether incident response plans account for the possibility of a network appliance being used as an initial access vector.
Source: SecurityWeek