Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.

Citrix vulnerabilities exploited

Citrix on Wednesday announced patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical-severity flaw.

The critical bug, tracked as CVE-2026-19490 (CVSS score of 9.3), is described as an authentication bypass using an alternative path, and impacts NetScaler appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.

It can be exploited by remote, unauthenticated attackers without user interaction, cybersecurity firm Rapid7 says.

Per Citrix’s advisory, the security defect impacts NetScaler ADC and NetScaler Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS.

NetScaler ADC and Gateway versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1-37.277 contain fixes for this flaw and for CVE-2026-19489, a high-severity memory overflow issue that could lead to unexpected behavior or denial-of-service (DoS) if SIP ALG is enabled at an LSN group configuration.

“Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities. Customers need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerabilities,” Citrix says.

Advertisement. Scroll to continue reading.

According to Rapid7, there are no indicators that threat actors are exploiting the authentication bypass issue, but NetScaler’s critical role within enterprise systems makes it an attractive target for hackers.

“NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality,” the cybersecurity firm notes.

Rapid7 expects threat actors to exploit the critical bug shortly, given that NetScaler appliances are typically deployed in enterprise DMZs and are publicly accessible.

“Organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild,” the company says.

Related: Critical GitLab Flaw Exploited Shortly After Disclosure

Related: Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

Related: Exploitation of Fresh Citrix NetScaler Vulnerability Begins

Related: 943 Patches Rolled Out With Oracle’s August 2026 Security Update

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.