Citrix urges admins to patch new NetScaler flaws as soon as possible
AI Generated Image

Citrix urges admins to patch new NetScaler flaws as soon as possible

BleepingComputer technology

Key Points:

  • Citrix has issued an urgent warning for customers to secure their NetScaler Gateway and NetScaler ADC appliances against two critical vulnerabilities, CVE-2026-19490 and CVE-2026-19489, which could allow remote attackers to bypass authentication or cause denial-of-service attacks.
  • CVE-2026-19490 enables privilege bypass when appliances are configured as AAA virtual servers or Gateways with SAML action enabled, while CVE-2026-19489 is a memory overflow flaw exploitable in DoS attacks when SIP ALG is enabled on large-scale NAT groups.
  • Administrators can check vulnerability exposure by inspecting specific configuration strings related to SAML actions, authentication servers, VPN servers, and SIP ALG settings on their NetScaler devices.
  • Citrix recommends upgrading affected appliances to the latest firmware versions, including NetScaler ADC and Gateway 14.1-73.32 or later, and advises reviewing the official security bulletin to assess and mitigate risks promptly.
  • Although these new vulnerabilities have not yet been exploited in the wild, Citrix urges patching other recently disclosed NetScaler flaws that have been actively attacked, with CISA mandating federal agencies to secure vulnerable Citrix systems within three days.

Trending Business

Trending Technology

Trending Health