CyberSecurityNews

Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials


Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).

Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could allow attackers to trigger denial-of-service conditions or bypass authentication entirely on unpatched appliances, putting enterprise remote access infrastructure at significant risk.

Critical Citrix NetScaler Vulnerability

The more severe of the two, CVE-2026-19490, carries a CVSS v4.0 base score of 9.3 and is classified under CWE-288, Authentication Bypass Using an Alternate Path. This flaw allows an attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.

The exploitability depends on the specific software build in use. On NetScaler 14.1-43.56 and later, as well as 13.1-61.28 and later, the vulnerability is exploitable only when the appliance is configured with a SAML action.

On earlier builds, however, any Gateway or AAA vserver configuration is sufficient to expose the flaw, making a broader set of deployments vulnerable. Given that authentication gateways are the primary control point for remote access, successful exploitation could grant attackers unauthorized entry into corporate networks without valid credentials.

The second vulnerability, CVE-2026-19489, scores 8.8 on the CVSS v4.0 scale and stems from a memory overflow issue tied to CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer.

This bug is triggered when SIP ALG, the Session Initiation Protocol Application Layer Gateway, is enabled within a Large Scale NAT (LSN) group configuration. Exploitation can lead to unpredictable appliance behavior or a full denial-of-service outage, disrupting critical network services that depend on the NetScaler for traffic management and NAT translation.

The vulnerabilities affect NetScaler ADC and NetScaler Gateway version 14.1 before build 73.32, version 13.1 before build 63.21, as well as the FIPS and NDcPP variants of these releases.

Notably, Secure Private Access Hybrid deployments that rely on customer-managed NetScaler instances are also exposed and require the same upgrades, though Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings.

Administrators can check exposure by reviewing their NetScaler configuration files for specific command strings. For CVE-2026-19489, searching for LSN group entries containing SIP ALG settings will confirm the precondition. For CVE-2026-19490, checking for SAML action configurations or existing authentication and VPN vserver entries will reveal whether the appliance meets the criteria for exploitation.

Cloud Software Group is urging all customers to upgrade immediately to NetScaler ADC and Gateway 14.1-73.32 or later, 13.1-63.21 or later, or the corresponding FIPS and NDcPP builds.

Given the network-facing nature of these appliances and the low complexity required for exploitation, security teams should treat patching as an urgent priority rather than a routine maintenance task.

The vulnerabilities were responsibly disclosed by Samarth Vashisht of JPMorgan Chase’s penetration testing team, underscoring the value of coordinated vulnerability research in protecting widely deployed enterprise infrastructure.

Organizations still running vulnerable builds should assume increased risk of targeted scanning once technical details circulate more broadly, a pattern historically seen with prior Citrix and NetScaler flaws.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link