Particle.news

Citrix Issues Emergency Patches for Two NetScaler Flaws Including Critical Authentication Bypass

Security teams must upgrade customer‑managed NetScaler appliances immediately because the bypass can let unauthenticated remote actors reach VPN and AAA entry points.

Overview

  • Citrix published fixes on Thursday for two NetScaler ADC and NetScaler Gateway vulnerabilities, naming the authentication bypass as CVE-2026-19490 and a memory overflow/DoS as CVE-2026-19489.
  • CVE-2026-19490 lets a remote, unauthenticated attacker bypass login checks on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server when specific SAML or version conditions are met.
  • CVE-2026-19489 is a separate high‑severity memory overflow that can cause crashes or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group, a narrow configuration precondition.
  • Citrix published exact fixed builds (for example 14.1-73.32 and 13.1-63.21), offered configuration checks administrators can run (for example searching for add authentication samlAction or add lsn group.*sipalg.*), and said Citrix‑managed cloud services are already updated while customer‑managed appliances must be patched.
  • Researchers say there are no confirmed in‑the‑wild exploits yet but warn exploit attempts are likely because thousands of NetScaler instances are internet‑exposed; administrators should apply the recommended builds, verify configurations, and expect possible rapid abuse.