Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.

Citrix vulnerabilities exploited

Citrix on Wednesday announced patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical-severity flaw.

The critical bug, tracked as CVE-2026-19490 (CVSS score of 9.3), is described as an authentication bypass using an alternative path, and impacts NetScaler appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server.

It can be exploited by remote, unauthenticated attackers without user interaction, cybersecurity firm Rapid7 says.

Per Citrix’s advisory, the security defect impacts NetScaler ADC and NetScaler Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS.

NetScaler ADC and Gateway versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1-37.277 contain fixes for this flaw and for CVE-2026-19489, a high-severity memory overflow issue that could lead to unexpected behavior or denial-of-service (DoS) if SIP ALG is enabled at an LSN group configuration.

“Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities. Customers need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerabilities,” Citrix says.

Advertisement. Scroll to continue reading.

According to Rapid7, there are no indicators that threat actors are exploiting the authentication bypass issue, but NetScaler’s critical role within enterprise systems makes it an attractive target for hackers.

“NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality,” the cybersecurity firm notes.

Rapid7 expects threat actors to exploit the critical bug shortly, given that NetScaler appliances are typically deployed in enterprise DMZs and are publicly accessible.

“Organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild,” the company says.

Related: Critical GitLab Flaw Exploited Shortly After Disclosure

Related: Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

Related: Exploitation of Fresh Citrix NetScaler Vulnerability Begins

Related: 943 Patches Rolled Out With Oracle’s August 2026 Security Update

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.