Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› The eight-hour sleep rule is outdated. Here’s how much you really need› Blizzard explains why WoW: Forever won't have Summoning Stones, says 'easy quick access to teleports shrink the world' and 'easily erodes' its core design pillars› UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live› Ethiopia warns Eritrea it will defend itself after troops cross border› Man City charges LIVE: Triple punishment agreement as defiant Enzo Maresca takes grilling› How to watch Greece vs England: FREE streams and TV channels› Dual Arc hero Daryz retired to stud› Singapore GP: Ferrari ahead into final Sprint Qualifying pole battle LIVE!› Djokovic suffers shock second-round exit in Shanghai and Fery beaten› Wolff: People who think Mercedes favour Antonelli should watch Teletubbies› The eight-hour sleep rule is outdated. Here’s how much you really need› Blizzard explains why WoW: Forever won't have Summoning Stones, says 'easy quick access to teleports shrink the world' and 'easily erodes' its core design pillars› UN says Pentagon plan to livestream execution of Fort Hood shooter would amount to torture – US politics live› Ethiopia warns Eritrea it will defend itself after troops cross border› Man City charges LIVE: Triple punishment agreement as defiant Enzo Maresca takes grilling› How to watch Greece vs England: FREE streams and TV channels› Dual Arc hero Daryz retired to stud› Singapore GP: Ferrari ahead into final Sprint Qualifying pole battle LIVE!› Djokovic suffers shock second-round exit in Shanghai and Fery beaten› Wolff: People who think Mercedes favour Antonelli should watch Teletubbies
Technology

Citrix gives NetScaler admins another critical reason to patch

The Register ·
Citrix gives NetScaler admins another critical reason to patch

Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws.

CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS).

It carries a CVSS v4.0 score of 9.5.

The affected configurations depend on the software version.

Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration.

Citrix's advisory lists the affected builds and required updates.

Secure Private Access Hybrid deployments using NetScaler instances also need patching.

Citrix classifies the flaw as CWE-119: improper restriction of operations within a memory buffer.

Customers must update their own deployments.

Citrix says it handles the necessary updates for its managed cloud services and Adaptive Authentication.

Citrix did not say whether this vulnerability was already exploited as a zero-day before disclosure, but credited Michael Tucker, Chew Keong Tan, and Alex Bernier at JPMorgan Chase's XOR Team, along with Maxim Suhanov, for the discovery.

Google researchers said a campaign exploiting CVE-2026-88772 had been underway since at least early September, with organizations in government, finance, legal, and education across North America and Europe likely affected.

Citrix disclosed the flaw weeks later as part of a release that patched eight vulnerabilities.

Citrix disclosed another exploited flaw, CVE-2026-88779, last Friday that carries a severity score of 8.7.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›