Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to urgently secure NetScaler Gateway and NetScaler ADC appliances against CVE-2026-19490 and CVE-2026-19489, which can lead to authentication bypass and denial-of-service attacks under specific configurations. The company also urged rapid patching to the recommended firmware builds after previous NetScaler flaws were exploited in the wild, while CISA continues to track Citrix vulnerabilities in its KEV Catalog. #Citrix #NetScaler #CVE-2026-19490 #CVE-2026-19489 #CISA

Keypoints

  • CVE-2026-19490 can let unauthenticated attackers bypass authentication on certain NetScaler setups.
  • CVE-2026-19489 may trigger denial-of-service attacks when SIP ALG is enabled in a large-scale NAT group.
  • Admins can check for vulnerable configurations by inspecting SAML action, vserver, and lsn group settings.
  • Citrix recommends upgrading to the latest supported NetScaler ADC and NetScaler Gateway builds.
  • CISA and Citrix have highlighted repeated real-world abuse of past NetScaler flaws, making patching urgent.

Read More: https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/