Breaking
SecurityConfirmed

Citrix NetScaler flaws: patch gap may invite attackers

Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.

··2 hours ago·3 min read
closeup photo of turned-on blue and white laptop computer
Photo by Philipp Katzenberger on Unsplash

Citrix is pushing administrators to move quickly on two newly disclosed NetScaler vulnerabilities, warning that the more serious of the two could let unauthenticated attackers bypass authentication entirely. The advisory, issued Wednesday, covers NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances, and it lands just days after the company had to push patches for two other flaws that were already being exploited.

Auth bypass flaw takes top billing

The most severe issue, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication. The condition depends on how the appliance is configured: it must be set up as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), and the impact varies by NetScaler firmware version and whether SAML Action is configured.

Admins can check if their appliance is exposed to attacks targeting CVE-2026-19490 by inspecting the NetScaler configuration for the SAML action configuration string (add authentication samlAction .*) and Auth or VPN vserver strings (add authentication vserver .* and add vpn vserver .*).

Second flaw opens DoS door

The second vulnerability, a high-severity memory overflow tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks. The precondition is that SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.

Security teams can determine whether their NetScaler appliances meet the preconditions for CVE-2026-19489 exploitation by searching their configuration for the "add lsn group.*sipalg.*" string.

Advisory urges specific upgrades

Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to the following builds, as applicable:

  • NetScaler ADC and NetScaler Gateway 14.1-73.32 or later
  • NetScaler ADC and NetScaler Gateway 13.1-63.21 or later
  • NetScaler ADC FIPS 14.1-73.32 FIPS or later
  • NetScaler ADC FIPS and NDcPP 13.1-37.277 or later

Citrix's explicit warning

"We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,"

— Citrix warned in Wednesday's advisory.

The company added that the bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.

Recent history of rapid exploitation

While these two new flaws have not been flagged as exploited in attacks, Citrix urged admins to patch two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) on March 23, just days before attackers began abusing them in the wild.

CISA added the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.

Over the last five years, the U.S. cybersecurity agency has flagged 22 Citrix vulnerabilities as exploited in the wild, six of them also abused in ransomware attacks.

Exposed instances remain plentiful

The ShadowServer Foundation now tracks over 22,000 NetScaler ADC and nearly 1,800 NetScaler Gateway instances exposed online. However, it does not provide information on the number of honeypots or how many may be vulnerable to attacks targeting CVE-2026-19489 and CVE-2026-19490.

The stakes for network defenders

The timing of these advisories, coming on the heels of the March exploits, suggests that the window for patching could be short. Even without confirmed exploitation of these two flaws, the pattern of Citrix vulnerabilities being rapidly weaponized after disclosure indicates that unpatched appliances may soon become targets. With thousands of instances still exposed, the practical takeaway for administrators is clear: review configurations, identify affected systems, and apply the recommended builds without delay.

#citrix#netscaler#vulnerability#cve-2026-19489#cve-2026-19490#patch

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories