Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix NetScaler Flaws Leave Remote Access Systems Vulnerable, Urgent Patching Recommended

A pair of newly disclosed vulnerabilities in Citrix’s NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances has left administrators scrambling to patch their systems. The flaws, which can be exploited remotely without authentication, highlight the ongoing threat posed by unpatched software vulnerabilities.

The most severe of the two vulnerabilities, tracked as CVE-2026-19490, allows an attacker with no privileges to bypass authentication when the appliance is configured in a specific way. This configuration includes situations where SAML Action is enabled and the NetScaler firmware version meets certain criteria. Admins can check if their appliances are vulnerable by inspecting their configuration for specific strings.

The second vulnerability, CVE-2026-19489, is a high-severity memory overflow flaw that can be exploited in denial-of-service (DoS) attacks when SIP ALG is enabled on a large-scale NAT group configuration. Security teams can determine whether their Citrix NetScaler appliances are vulnerable by inspecting their configuration for specific strings related to SIP ALG.

Citrix has advised customers to upgrade their vulnerable appliances to the latest versions, which include NetScaler ADC and Gateway 14.1-73.32 or later, as well as other versions depending on the appliance type. The company emphasized that patching is essential to prevent exploitation of these vulnerabilities, especially given the recent history of attacks targeting similar flaws.

In fact, Citrix has faced a string of security issues in recent years, with over 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances exposed online. Moreover, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged several Citrix vulnerabilities as exploited in the wild, including one added to its Known Exploited Vulnerabilities Catalog just last month.

The urgency of patching these vulnerabilities is underscored by the fact that once attackers gain valid credentials, prevention scores drop sharply. According to recent research, only 37% of an attacker’s actions are blocked after initial access, highlighting the need for vigilant security practices and prompt remediation of vulnerabilities.

In light of this news, administrators responsible for Citrix NetScaler appliances should immediately review their system configurations, assess whether they are affected by these vulnerabilities, and take steps to patch their systems as soon as possible. This includes reviewing the official security bulletin and upgrading impacted appliances to recommended builds. By doing so, organizations can help prevent exploitation of these flaws and maintain the integrity of their remote access systems.


Source: Bleeping Computer — 2026-08-20