Citrix is urging administrators to patch a Citrix NetScaler authentication bypass vulnerability rated 9.3 on the CVSS v4.0 scale, alongside a second high-severity flaw that opens the door to denial-of-service attacks. Both affect NetScaler Gateway and NetScaler ADC appliances, and Citrix wants them patched immediately.

What the two vulnerabilities actually do

The more severe of the pair, CVE-2026-19490, lets remote attackers bypass authentication entirely without needing any privileges. It applies when an appliance is configured as an AAA virtual server or as a Gateway (covering SSL VPN, ICA Proxy, CVPN, and RDP Proxy modes), depending on the firmware version and whether SAML Action is configured. IONIX classifies it as CWE-288, meaning the bypass exploits an alternate authentication path rather than breaking the primary mechanism head-on. Administrators can check their exposure by scanning the NetScaler configuration for add authentication samlAction .* strings alongside Auth or VPN vserver entries (add authentication vserver .* and add vpn vserver .*).

The second flaw, CVE-2026-19489, is a memory overflow bug that remote unauthenticated attackers can exploit to knock appliances offline. It requires SIP ALG (Session Initiation Protocol Application Layer Gateway) to be enabled on a large-scale NAT group configuration. Teams can check for the precondition by searching their configuration for the string add lsn group.*sipalg.*.

Citrix NetScaler authentication bypass: upgrade paths and log retention

Citrix has published specific firmware targets. Vulnerable appliances should be upgraded to NetScaler ADC and NetScaler Gateway 14.1-73.32 or later, or 13.1-63.21 or later, depending on the deployment. FIPS builds require NetScaler ADC FIPS 14.1-73.32 or later; NDcPP environments need 13.1-37.277 or later. SecurAccess ZTNA Hybrid deployments (formerly Secure Private Access Hybrid) that use customer-managed NetScaler instances are also in scope and must be upgraded.

Before touching anything, though, there is a step teams should not skip. F5 Labs advises that administrators archive all NetScaler authentication, access, and VPN logs covering at least the last 90 days before performing any upgrades. That window preserves the forensic record needed to determine whether a vulnerable appliance was accessed prior to patching, which becomes rather important if an active exploitation campaign starts targeting these CVEs.

‘We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,’ Citrix stated. The bulletin covers supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds.

Context: Citrix and CISA’s long history with NetScaler flaws

Neither CVE-2026-19490 nor CVE-2026-19489 has been flagged as actively exploited at the time of writing, but that status can change fast. In March, Citrix patched two other NetScaler vulnerabilities, CVE-2026-3055 and CVE-2026-4368, on 23 March. Attackers began abusing them in the wild within days. CISA added CVE-2026-3055 to its Known Exploited Vulnerabilities catalogue on 30 March and gave federal agencies three days to secure affected appliances.

That episode fits a familiar pattern. Over the last five years, CISA has flagged 22 Citrix vulnerabilities as exploited in the wild, six of which were also abused in ransomware attacks. The cadence of discovery, brief quiet period, then active exploitation is well established enough that the ‘not yet exploited’ label is better read as a countdown than a clearance.

The ShadowServer Foundation currently tracks over 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances exposed on the public internet. ShadowServer has not published a breakdown of how many of those exposed instances meet the specific preconditions for CVE-2026-19489 or CVE-2026-19490 exploitation, so the actual attack surface for each flaw is not fully quantified.

For teams prioritising remediation order: with a CVSS v4.0 score of 9.3, the Citrix NetScaler authentication bypass tracked as CVE-2026-19490 should sit at the top of the queue. A DoS flaw is damaging; an unauthenticated authentication bypass on a remote access gateway is an entirely different category of problem. Archive those logs, identify your firmware branch, and upgrade.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version