New NetScaler security flaws have prompted Citrix to urge administrators to update affected appliances as soon as possible. The two vulnerabilities affect NetScaler Gateway remote-access products and NetScaler ADC networking appliances.
The more serious issue, CVE-2026-19490, could allow an unauthenticated remote attacker to bypass authentication under certain conditions. A second flaw, CVE-2026-19489, could let an attacker disrupt services through a denial-of-service attack.
Neither vulnerability has been confirmed as actively exploited. However, organisations should act quickly, as NetScaler products frequently attract attacker attention.
Authentication bypass affects specific NetScaler setups
CVE-2026-19490 affects NetScaler appliances configured as an AAA virtual server or Gateway. This can include SSL VPN, ICA Proxy, CVPN and RDP Proxy deployments.
The authentication bypass risk depends on the installed firmware version and whether the appliance uses SAML Action configuration. An attacker who meets the required conditions could bypass the normal login process without valid credentials.
Administrators can review their NetScaler configuration for SAML Action settings and authentication or VPN virtual server entries. These settings can help determine whether the affected configuration exists in their environment.
Because Gateway appliances often provide remote access to internal systems, an authentication bypass could expose important network services to unauthorised users.
Second flaw can cause service disruption
The second vulnerability, CVE-2026-19489, is a high-severity memory overflow issue. It can support denial-of-service attacks against vulnerable systems.
An unauthenticated attacker could exploit the flaw remotely when SIP Application Layer Gateway is enabled on a large-scale NAT group configuration. Successful attacks could interrupt access to services running through the affected appliance.
Security teams should check for large-scale NAT group settings that enable SIP ALG. That configuration creates the conditions required for exploitation of CVE-2026-19489.
Although a denial-of-service flaw does not provide direct access to a network, it can still cause serious operational problems. Remote-access outages can interrupt employees, customers and critical business processes.
Citrix publishes updated NetScaler builds
Citrix has released fixes for supported NetScaler ADC and Gateway versions. Affected standard installations should update to version 14.1-73.32 or later, or version 13.1-63.21 or later.
For FIPS deployments, administrators should install version 14.1-73.32 FIPS or later. NetScaler ADC FIPS and NDcPP deployments should update to version 13.1-37.277 or later.
The guidance also applies to customer-managed NetScaler systems used by SecurAccess ZTNA Hybrid deployments. Administrators should identify all appliances in scope before beginning remediation.
NetScaler appliances remain a high-value target
Citrix has previously issued urgent patch guidance for other NetScaler vulnerabilities shortly before attackers began exploiting them. Earlier in 2026, threat actors started abusing two NetScaler flaws within days of a patch warning.
Over the past five years, US authorities have listed 22 Citrix vulnerabilities as exploited in real attacks. Six of those flaws also appeared in ransomware campaigns.
More than 22,000 NetScaler ADC appliances and nearly 1,800 NetScaler Gateway instances remain exposed online. Public exposure does not confirm that an appliance is vulnerable, but it highlights the scale of the potential attack surface.
Conclusion
The new NetScaler security flaws create authentication bypass and service-disruption risks for affected configurations. Administrators should review their deployments, identify vulnerable settings and apply the recommended firmware updates without delay.


0 responses to “NetScaler Security Flaws Require Immediate Patching”