Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix Issues Urgent Warning for NetScaler Security Flaws, Patches Now Available

Citrix has sounded the alarm, warning administrators to immediately patch two critical vulnerabilities affecting its NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The flaws, tracked as CVE-2026-19490 and CVE-2026-19489, can be exploited by attackers to bypass authentication or launch denial-of-service (DoS) attacks.

The most severe of the two, CVE-2026-19490, allows remote attackers without privileges to bypass authentication when the appliance is configured in specific ways. This means that if an attacker can gain access to a vulnerable NetScaler Gateway or ADC system, they may be able to move freely within the network without being detected. Citrix has provided instructions for administrators to check if their appliances are vulnerable, which involve inspecting configuration settings for certain strings.

The second vulnerability, CVE-2026-19489, is a high-severity memory overflow security flaw that can be exploited in DoS attacks when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a large-scale NAT group configuration. This type of attack can cause a device to crash or become unresponsive, leading to disruptions and potential data loss.

Citrix has advised customers to upgrade their vulnerable NetScaler ADC and NetScaler Gateway appliances to the latest versions, which are available now. The company emphasizes that it is crucial for administrators to review the official security bulletin, assess whether their deployments are affected, and apply the necessary patches as soon as possible.

This warning comes at a critical time, as Citrix has already seen attackers exploiting similar vulnerabilities in the past. In March, the company warned about two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) that were later abused in attacks. The US Cybersecurity and Infrastructure Security Agency (CISA) added one of these vulnerabilities to its Known Exploited Vulnerabilities Catalog on March 30, requiring federal agencies to secure their Citrix appliances within three days.

The frequency and severity of these security flaws highlight the importance of staying up-to-date with the latest patches and updates. As many as 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances are exposed online, making them potential targets for attackers. Administrators must take immediate action to protect their systems and prevent exploitation.

In practical terms, this means that administrators should prioritize patching these vulnerabilities immediately, even if they believe their systems are not vulnerable. The consequences of delayed patching can be severe, including data loss, system crashes, and compromised security. By staying proactive and vigilant, organizations can minimize the risk of attack and maintain the integrity of their networks.


Source: Bleeping Computer — 2026-08-20