logo

Citrix urges admins to patch new NetScaler flaws as soon as possible

ID: 618ac9c8-31f0-53cb-aa0b-e6193e64a74c

STIX ID: report--618ac9c8-31f0-53cb-aa0b-e6193e64a74c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Sergiu Gatlan

...
...

Citrix warned of two vulnerabilities in NetScaler ADC and NetScaler Gateway — CVE-2026-19490, an authentication-bypass issue affecting appliances configured with SAML Action or as AAA/Gateway vservers, and CVE-2026-19489, a high-severity memory overflow leading to DoS when SIP ALG is enabled on large-scale NAT groups. The bulletin gives configuration strings administrators can search to detect vulnerable appliances, lists fixed firmware builds to upgrade to, and notes that while these flaws have not yet been reported exploited, Citrix urged immediate patching given recent rapid exploitation of other NetScaler CVEs and the large number of exposed instances online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.