For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and NetScaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution.

This week’s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language) identity provider (IdP). Older versions are also vulnerable when configured as a SAML service provider (SP), Citrix said in an advisory about the vulnerability, which it is tracking as CVE-2026-107406.

Citrix rated the vulnerability critical, with a CVSS v4.0 score of 9.5, and stated it was “not aware of any unmitigated exploits of this vulnerability.”

Nevertheless, it encouraged affected customers to upgrade to patched versions as soon as possible: 13.1-64.29 or later for the 13.1 series, and 14.1-73.46 or later for the 14.1 series of ADC and Gateway, and 13.1.37.283 or later for ADC 13.1-FIPS or 13.1-NDcPP.

A Third Week of Critical Patches

Citrix’s recent run of bad news began on September 27, a Sunday, when it advised users of NetScaler ADC and Gateway to take their systems offline and patch two critical unauthenticated remote code execution vulnerabilities immediately, as both were under active attack. The urgency prompted one security researcher to warn that “Monday will be too late.”

More flaws turned up the following week, including another memory overflow vulnerability (CVE-2026-88779), rated 8.7 on the CVSS 4.0 scale and confirmed by Citrix to be actively exploited to cause denial of service. That same week, Citrix also released NetScaler ADC and Gateway version 14.1-60.58, patching a critical memory overread vulnerability tracked as CVE-2026-3055.

Whether the issue is memory overflows or memory overreads, Citrix appears to be facing a sustained and serious challenge securing its NetScaler product line, with administrators advised to apply the latest patches without delay.

This article first appeared on Network World.