Exploitation of critical authentication bypass expected in Citrix NetScaler

Exploitation of critical authentication bypass expected in Citrix NetScaler

Citrix on Wednesday announced patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including one critical severity vulnerability.

The critical flaw, tracked as CVE-2026-19490 (CVSS score 9.3), is described as an authentication bypass using an alternate path and affects NetScaler appliances configured as a gateway (SSL VPN, ICA proxy, CVPN, RDP proxy) or AAA virtual server.

It can be exploited by remote, unauthenticated attackers without user interaction, says cybersecurity firm Rapid7.

According to Citrix advisoryThe security flaw affects NetScaler ADC and NetScaler Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS.

NetScaler ADC and Gateway versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-FIPS and 13.1-NDcPP 13.1-37.277 contain fixes for this bug and for CVE-2026-19489, a high-level memory overflow issue that results in unexpected behavior could cause Denial of Service (DoS) if SIP ALG is enabled in an LSN group configuration.

“Secure Private Access Hybrid deployments with NetScaler instances are also affected by the vulnerabilities. Customers must update these NetScaler instances to the recommended NetScaler builds to resolve the vulnerabilities,” Citrix said.

Advertising. Scroll to continue reading.

Accordingly Rapid7There is no evidence that threat actors are exploiting the authentication bypass issue, but NetScaler’s critical role in enterprise systems makes it an attractive target for hackers.

“NetScaler ADC and NetScaler Gateway are widely used enterprise networking products that are typically positioned at or near the network perimeter. NetScaler ADC provides application provisioning, traffic management, load balancing, SSL/TLS offloading and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality,” the cybersecurity company notes.

Rapid7 expects threat actors to exploit the critical flaw shortly, as NetScaler appliances are typically deployed in corporate DMZs and are publicly accessible.

“Organizations should prioritize patching affected systems in an emergency as Citrix products are high-value targets that are typically quickly exploited,” the company says.

Related: Critical GitLab flaw was exploited shortly after disclosure

Related: Citrix fixes NetScaler vulnerabilities, including a new “HTTP/2 bomb” attack

Related: Exploitation of the new Citrix NetScaler vulnerability begins

Related: 943 patches were introduced in Oracle’s August 2026 security update

Leave a Reply

Your email address will not be published. Required fields are marked *