Citrix issues critical security updates for its NetScaler devices

Wait 5 sec.

Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances, are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already been updated.However, it added, “at this point [August 19] the NetScaler images available on cloud marketplaces (AWS, Azure, GCP) have not been updated. If you need to update the images to the versions containing the fix, please download them from Citrix downloads page.”Analysts and cybersecurity consultants agreed that these patches should be urgently applied, given the sensitive and risky nature of gateways. In fact, noted Charlie Winckless, VP/analyst at Gartner, his firm now identifies the increase in perimeter threats “as the highest signal as used by threat actors,” with internet-exposed appliances the most critical. “In the past,” he said, “new Citrix issues have been exploited rapidly by attackers due to their location in the application path.”Of the two flaws, “the authentication bypass [CVE-2026-19490] is the one that should make people move tonight,” said cybersecurity consultant Brian Levine, executive director of FormerGov. “NetScaler sits at the network edge, facing the internet, and a critical-rated, pre-authentication bypass on an edge appliance is about as high-value as a target gets.” And because authentication bypasses in Citrix gateways are almost always weaponized, and usually quickly, he said, “I suggest organizations patch the authentication bypass on an emergency basis, not on their normal maintenance cycle.”Levine added that this is not a “patch and you’re done” situation; defenders also need to rotate credentials, kill active sessions, and hunt for signs of prior access before they close the incident.“A CVSS 9.3 means a remote attacker with no credentials and no user interaction can defeat the login on a device whose entire job is to be a secure front door,” he said. “If you’re running it as a Gateway or AAA virtual server, you have to assume this is a ‘when,’ not an ‘if.’”Fritz Jean-Louis, principal cybersecurity advisor at Info-Tech Research Group, echoed Levine’s concerns. “Even when a vulnerability is rated lower than a remote code execution flaw, organizations should not underestimate the risk when it affects a security gateway,” Jean-Louis said. The vulnerability “can’t just be added to the patch queue, because it has the potential to undermine one of the controls organizations depend on to keep unauthorized users out.”Mike Wilkes, enterprise CISO at Aikido Security, added that rapid application of these fixes is crucial now that the announcement has alerted attackers to the flaws. That means it’s a race to see who acts the fastest: the good guys or the bad guys. “There are no public indicators that these two new flaws are being exploited at the moment, but that is likely to change within hours, given the ability of threat actors to weaponize the update patch to discern the exploit details,” he said, given that a CVSS 9.3 authentication bypass flaw on a NetScaler Gateway or AAA server is precisely the kind of vulnerability defenders do not want sitting on an internet-facing boundary, because a successful exploit could allow unauthorized access to resources behind the gateway, followed by credential or session abuse, reconnaissance, lateral movement and ultimately data theft or broader compromise.The second major hole flagged by Citrix, CVE-2026-19489, with an 8.8 CVSS score, is less of a concern but still worrisome, he noted. “It requires SIP ALG to be enabled on a large-scale NAT group, so the vulnerable population should be considerably smaller,” Wilkes said. “Nevertheless, a remotely triggerable memory overflow capable of producing unpredictable behavior or denial of service is consequential on infrastructure whose purpose is keeping applications and remote users connected. An attacker does not necessarily need to steal data for an attack to be damaging: repeatedly destabilizing or crashing an ADC or gateway can interrupt VPN access, customer-facing applications and other dependent services at precisely the moment an organization needs them.”In addition, Wilkes said, CISOs should be worried about the “accumulated risk history around NetScaler and Citrix edge infrastructure.”“CISA has flagged 22 Citrix vulnerabilities as known exploits over the last five years, six of them associated with ransomware,” he pointed out. “That history matters because attackers have repeatedly demonstrated that they understand the strategic value of these perimeter systems and know how to abuse them. The risk calculation is not simply the theoretical severity of CVE-2026-19489 or CVE-2026-19490. It is the combination of serious vulnerability classes, internet exposure, privileged network position and a demonstrated adversary appetite for weaponizing Citrix flaws soon after disclosure. There is a hungry population of attackers that has heard the Pavlovian bell ring that it’s feeding time again on Citrix stacks.”