VORANT. Threat Intelligence Research Sign in Create a free account

Citrix NetScaler ADC/Gateway RCE flaw patched

routine vulnerability technologyinfrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advises patching a remote code execution and denial-of-service vulnerability in Citrix NetScaler ADC and Gateway.

CERT-FR published an advisory for a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-107406. The flaw allows a remote attacker to execute arbitrary code and cause a denial of service on affected appliances. Affected versions include NetScaler ADC 13.1-FIPS before 13.1-NDcPP 13.1.37.283, 13.1.x before 13.1-64.29, 14.1-FIPS before 14.1-73.46 FIPS, and 14.1.x before 14.1-73.46, as well as NetScaler Gateway 13.1.x before 13.1-64.29 and 14.1.x before 14.1-73.46.

Citrix has released a security bulletin (CTX697191, dated 09 October 2026) with patched versions. No in-the-wild exploitation is mentioned in the advisory. Given the history of NetScaler ADC/Gateway vulnerabilities being targeted shortly after disclosure (e.g., Citrix Bleed), defenders running affected versions should prioritize patching promptly, especially for internet-facing Gateway deployments used for remote access, and monitor for anomalous activity on these appliances.

No indicators of compromise, threat actor attribution, or malware association are provided in this advisory; it is a vendor patch notification distributed through the French national CERT.

Mentioned in this report

Vulnerabilities CVE-2026-107406

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1285

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,164 reports from 148 sources, 494 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs