• News/
  • bleepingcomputer-20260820121438

Citrix urges admins to patch new NetScaler flaws as soon as possible

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 20, 2026
·
Updated

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. Admins can check if an appliance is vulnerable to attacks targeting CVE-2026-19490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction .*) string and Auth or VPN vserver ('add authentication vserver .*' and 'add vpn vserver .*') strings. The second, a high-severity memory overflow security flaw tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration. Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the "add lsn group.*sipalg.*" string. Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to: "We strongly recommend that customers review the official NetScaler ADC and NetScaler G...

Read full article

Affected Software

3 affected components
Citrix NetScaler Gateway
Citrix NetScaler ADC
Citrix SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid)

Frequently Asked Questions

1

Which NetScaler deployments are affected by CVE-2026-19490?

The authentication-bypass flaw can affect NetScaler Gateway secure remote access solutions and NetScaler ADC appliances configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy. Exposure depends on the NetScaler firmware version and whether SAML Action is configured.

2

How can administrators check for configuration exposure to CVE-2026-19490?

Administrators can inspect the NetScaler configuration for SAML action entries matching "add authentication samlAction .*" and for authentication or VPN virtual-server entries matching "add authentication vserver .*" and "add vpn vserver .*".

3

What could an attacker do with CVE-2026-19490?

A remote attacker without privileges may be able to bypass authentication on affected configurations.

4

When is CVE-2026-19489 exploitable?

The high-severity memory-overflow flaw can be used by remote unauthenticated actors for denial-of-service attacks when SIP ALG is enabled on a large-scale NAT group configuration.

5

What action does Citrix recommend?

Citrix urges customers to secure affected NetScaler systems immediately and to patch the flaws as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203