Citrix NetScaler flaws: patch gap may invite attackers
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
Citrix is pushing administrators to move quickly on two newly disclosed NetScaler vulnerabilities, warning that the more serious of the two could let unauthenticated attackers bypass authentication entirely. The advisory, issued Wednesday, covers NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances, and it lands just days after the company had to push patches for two other flaws that were already being exploited.
Auth bypass flaw takes top billing
The most severe issue, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication. The condition depends on how the appliance is configured: it must be set up as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), and the impact varies by NetScaler firmware version and whether SAML Action is configured.
Admins can check if their appliance is exposed to attacks targeting CVE-2026-19490 by inspecting the NetScaler configuration for the SAML action configuration string (add authentication samlAction .*) and Auth or VPN vserver strings (add authentication vserver .* and add vpn vserver .*).
Second flaw opens DoS door
The second vulnerability, a high-severity memory overflow tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks. The precondition is that SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.
Security teams can determine whether their NetScaler appliances meet the preconditions for CVE-2026-19489 exploitation by searching their configuration for the "add lsn group.*sipalg.*" string.
Advisory urges specific upgrades
Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to the following builds, as applicable:
- NetScaler ADC and NetScaler Gateway 14.1-73.32 or later
- NetScaler ADC and NetScaler Gateway 13.1-63.21 or later
- NetScaler ADC FIPS 14.1-73.32 FIPS or later
- NetScaler ADC FIPS and NDcPP 13.1-37.277 or later
Citrix's explicit warning
"We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"
— Citrix warned in Wednesday's advisory.
The company added that the bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.
Recent history of rapid exploitation
While these two new flaws have not been flagged as exploited in attacks, Citrix urged admins to patch two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) on March 23, just days before attackers began abusing them in the wild.
CISA added the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
Over the last five years, the U.S. cybersecurity agency has flagged 22 Citrix vulnerabilities as exploited in the wild, six of them also abused in ransomware attacks.
Exposed instances remain plentiful
The ShadowServer Foundation now tracks over 22,000 NetScaler ADC and nearly 1,800 NetScaler Gateway instances exposed online. However, it does not provide information on the number of honeypots or how many may be vulnerable to attacks targeting CVE-2026-19489 and CVE-2026-19490.
The stakes for network defenders
The timing of these advisories, coming on the heels of the March exploits, suggests that the window for patching could be short. Even without confirmed exploitation of these two flaws, the pattern of Citrix vulnerabilities being rapidly weaponized after disclosure indicates that unpatched appliances may soon become targets. With thousands of instances still exposed, the practical takeaway for administrators is clear: review configurations, identify affected systems, and apply the recommended builds without delay.
Sources
- BleepingComputer Original source
Continue Reading
Android Banking Trojans Gain On-Device Fraud Tools
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
AI-Assisted Attacks Target Water Systems
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.
NCSC's Agentic AI Controls Raise the Stakes for Autonomy
UK NCSC issues interim guidance urging sandboxing, human oversight, and access limits for agentic AI systems.