{"id":23447,"date":"2026-08-20T12:14:38","date_gmt":"2026-08-20T12:14:38","guid":{"rendered":"https:\/\/scannn.com\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible\/"},"modified":"2026-08-20T12:14:38","modified_gmt":"2026-08-20T12:14:38","slug":"citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible","status":"publish","type":"post","link":"https:\/\/scannn.com\/lv\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible\/","title":{"rendered":"Citrix urges admins to patch new NetScaler flaws as soon as possible"},"content":{"rendered":"\n<div>\n<p style=\"text-align:center\"><\/p>\n<p>Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.<\/p>\n<p>The most severe of the two, tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-19490\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-19490<\/a>, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.<\/p>\n<p>Admins can check if an appliance is vulnerable to attacks targeting CVE-2026-19490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction .*) string and Auth or VPN vserver (&#8216;add authentication vserver .*&#8217; and &#8216;add vpn vserver .*&#8217;) strings.<\/p>\n<div align=\"center\" style=\"width:98%; margin:0 auto; padding:5px; text-align:center; background:#f0f0f0; border:1px solid #ccc; border-radius:6px;\">\n <a href=\"https:\/\/wiz.io\/lp\/ai-threat-readiness-playbook?utm_source=bleepingcomputer&amp;utm_medium=display&amp;utm_campaign=FY27Q2_INB_FORM_AI-Threat-Readiness-Playbook&amp;sfcid=701Vh00000cnU0lIAE&amp;utm_term=FY27-bleepingcomputer-article-970x250-August&amp;utm_content=AITR-Playbook\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/w\/w-AITR-Playbook.jpg\" alt=\"image\" style=\"margin-top: 0px;\"\/><\/a>\n<\/div>\n<p>The second, a high-severity memory overflow security flaw tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-19489\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-19489<\/a>, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.<\/p>\n<p>Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the &#8220;add lsn group.*sipalg.*&#8221; string.<\/p>\n<p>Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:<\/p>\n<ul>\n<li>NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,<\/li>\n<p>&#13;<\/p>\n<li>NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,<\/li>\n<p>&#13;<\/p>\n<li>NetScaler ADC FIPS 14.1-73.32 FIPS or later,<\/li>\n<p>&#13;<\/p>\n<li>or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable<\/li>\n<p>&#13;\n<\/ul>\n<p>&#8220;We strongly recommend that customers review the <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696939\" target=\"_blank\" rel=\"nofollow noopener\">official NetScaler ADC and NetScaler Gateway security bulletin<\/a>, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,&#8221; <a href=\"https:\/\/community.citrix.com\/techzone-blogs\/110_security-updates\/security-update-netscaler-adc-and-netscaler-gateway-vulnerabilities-r1602\/\" target=\"_blank\" rel=\"nofollow noopener\">Citrix warned<\/a> on Wednesday.<\/p>\n<p>&#8220;The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.&#8221;<\/p>\n<p>While these security flaws have not been flagged as exploited in attacks, Citrix <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/citrix-urges-admins-to-patch-netscaler-flaws-as-soon-as-possible\/\" target=\"_blank\" rel=\"nofollow noopener\">urged admins<\/a> to patch two other NetScaler vulnerabilities (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-3055\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-3055<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-4368\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-4368<\/a>) on March 23, just days before attackers <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-citrix-netscaler-memory-flaw-actively-exploited-in-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">began abusing them in the wild<\/a>.<\/p>\n<p>CISA\u00a0<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3055\" target=\"_blank\" rel=\"nofollow noopener\">added<\/a> the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.<\/p>\n<p>Over the last five years, the U.S. cybersecurity agency <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=citrix\" target=\"_blank\" rel=\"nofollow noopener\">has flagged 22 Citrix vulnerabilities<\/a> as exploited in the wild, six of them also abused in ransomware attacks.<\/p>\n<p>The ShadowServer Foundation now tracks <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/iot-devices\/time-series\/?date_range=7&amp;vendor=citrix&amp;type=application-delivery-controller&amp;model=netscaler&amp;dataset=count&amp;limit=100&amp;group_by=geo&amp;stacking=stacked\" target=\"_blank\" rel=\"nofollow noopener\">over 22,000 NetScaler ADC<\/a> and <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/iot-devices\/time-series\/?date_range=7&amp;vendor=citrix&amp;type=vpn&amp;model=gateway&amp;dataset=count&amp;limit=100&amp;group_by=geo&amp;stacking=stacked\" target=\"_blank\" rel=\"nofollow noopener\">nearly 1,800 NetScaler Gateway instances<\/a> exposed online. However, it does not provide information on the number of honeypots or how many may be vulnerable to attacks targeting CVE-2026-19489 and CVE-2026-19490.<\/p>\n<div class=\"article-callout\">\n<div class=\"article-media\">\n        <a href=\"https:\/\/hubs.li\/Q04sB3fb0\" target=\"_blank\" rel=\"noopener nofollow\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/p-blue-report-26.jpg\" alt=\"article image\"\/><br \/>\n        <\/a>\n    <\/div>\n<div class=\"article-body\">\n<p>Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.<\/p>\n<p>The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.<\/p>\n<p>        <a class=\"article-link\" href=\"https:\/\/hubs.li\/Q04sB3fb0\" target=\"_blank\" rel=\"noopener nofollow\">Get the report<\/a>\n    <\/div>\n<\/div><\/div>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible?utm_source=tldrit\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":23448,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[143],"tags":[],"class_list":["post-23447","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai"],"_links":{"self":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/comments?post=23447"}],"version-history":[{"count":0,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/posts\/23447\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media\/23448"}],"wp:attachment":[{"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/media?parent=23447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/categories?post=23447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scannn.com\/lv\/wp-json\/wp\/v2\/tags?post=23447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}