Citrix is urging administrators to immediately patch two newly disclosed vulnerabilities affecting its NetScaler Gateway secure remote access products and NetScaler ADC networking appliances. The most severe issue, tracked as CVE-2026-19490, could let remote attackers with no credentials bypass authentication when the appliance runs as an AAA virtual server or as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, depending on the firmware version and whether SAML Action is configured. Administrators can check for exposure by looking for configuration strings related to SAML action and authentication or VPN vservers.
The second flaw, a high-severity memory overflow tracked as CVE-2026-19489, can be exploited by remote unauthenticated attackers in denial-of-service attacks when SIP ALG is enabled on a large-scale NAT group configuration. Security teams can verify whether their NetScaler appliances meet the conditions for that exploit by inspecting configurations for the relevant LSN group SIP ALG string. Citrix advised upgrading vulnerable NetScaler ADC and NetScaler Gateway appliances to the recommended builds.
Citrix issued the warning on Wednesday, stating that the advisory covers supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. The company also noted that SecurAccess ZTNA Hybrid deployments, formerly known as Secure Private Access Hybrid, which use customer-managed NetScaler instances, are affected and should be upgraded. Citrix strongly recommended that customers review the official NetScaler security bulletin and assess whether their deployments are impacted.
While neither of the two new flaws has been flagged as exploited in attacks, Citrix pointed to recent history as a reason for urgency. On March 23, the company urged administrators to patch two other NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, and attackers began abusing them in the wild just days later. The Cybersecurity and Infrastructure Security Agency, or CISA, added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.
Over the past five years, CISA has flagged 22 Citrix vulnerabilities as exploited in the wild, with six of those also abused in ransomware attacks. The ShadowServer Foundation currently tracks more than 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances exposed online, though it does not indicate how many may be honeypots or vulnerable to the two newly reported flaws. The broader context shows that while initial access may be blocked, prevention measures often weaken once attackers obtain valid credentials, according to a separate report measuring defenses across millions of simulations in production environments.
More cybersecurity news from TechManNews.







