Cybersecurity

Citrix Urges NetScaler Administrators to Install Updates Addressing Two Critical Vulnerabilities

Citrix warned of two vulnerabilities in NetScaler ADC and NetScaler Gateway, one of which could allow remote authentication bypass, while the other could be used to disable devices. The company recommends upgrading affected versions immediately, although it has not yet observed exploitation of either vulnerability in attacks.

2026-08-20
3 min read
9 views
فريق تحرير certi.news
Citrix Urges NetScaler Administrators to Install Updates Addressing Two Critical Vulnerabilities

Citrix urged customers to secure NetScaler devices immediately after disclosing two vulnerabilities affecting the NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The primary concern is that one vulnerability could allow remote, unauthenticated attackers to bypass authentication, while the other could be exploited to carry out denial-of-service attacks.

Authentication Bypass in Specific Configuration Cases

The more serious vulnerability is tracked as CVE-2026-19490 and can be exploited by unauthenticated attackers to bypass authentication when the device is configured as an AAA-type virtual server or as a Gateway. The listed Gateway cases include SSL VPN, ICA Proxy, CVPN, and RDP Proxy.

Whether a device is affected depends on the firmware version and on whether the SAML Action configuration is enabled. Administrators can check whether the conditions associated with the vulnerability are present by examining the NetScaler configuration and searching for the following strings:

  • add authentication samlAction .*
  • add authentication vserver .*
  • add vpn vserver .*

Another Vulnerability Could Cause Service Disruption

The second vulnerability, tracked as CVE-2026-19489 and classified by Citrix as high severity, is an out-of-bounds memory access flaw. Remote, unauthenticated attackers can exploit it in denial-of-service attacks when the SIP ALG function, or Session Initiation Protocol Application Layer Gateway, is enabled within a large-scale NAT group configuration.

To determine whether device configurations meet the exploitation conditions, security teams should inspect the configuration for the string add lsn group.*sipalg.*.

Versions Recommended by Citrix

The company recommended upgrading affected NetScaler ADC and NetScaler Gateway devices to one of the following versions, depending on the deployment type:

  • NetScaler ADC and NetScaler Gateway 14.1-73.32 or later.
  • NetScaler ADC and NetScaler Gateway 13.1-63.21 or later.
  • NetScaler ADC FIPS 14.1-73.32 FIPS or later.
  • NetScaler ADC FIPS and NDcPP 13.1-37.277 or later.

The alert covers supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP versions. SecurAccess ZTNA Hybrid deployments, formerly known as Secure Private Access Hybrid, are also affected when they use customer-managed NetScaler instances.

Why Does This Alert Matter?

Citrix has not yet listed the two vulnerabilities as exploited in real-world attacks, but the history of previous vulnerabilities explains the urgency of updating. On March 23, the company urged administrators to address CVE-2026-3055 and CVE-2026-4368, days before attackers began actively exploiting them. CISA later added CVE-2026-3055 to its Known Exploited Vulnerabilities Catalog on March 30 and ordered federal agencies to secure affected Citrix devices within three days.

During the past five years, the U.S. cybersecurity agency identified 22 vulnerabilities in Citrix products that it said had been exploited in real-world attacks, six of which were also used in ransomware attacks. ShadowServer is currently tracking more than 22,000 exposed NetScaler ADC instances and approximately 1,800 exposed NetScaler Gateway instances on the internet, without determining how many devices may be exploitable through the two new vulnerabilities.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news