Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely
Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely
Read Time:3 Minute, 48 Second

Two new flaws, one very high severity score

Citrix has shipped patches for a pair of vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliances thousands of enterprises use to broker remote access, load balancing and SSL VPN connections. The more serious of the two, tracked as CVE-2026-19490, is an authentication-bypass flaw carrying a CVSS v4.0 score of 9.3 — near the top of the scale. A second issue, CVE-2026-19489, is a memory-overflow bug rated 8.8 that can crash affected devices.

NetScaler has a well-earned reputation as a favorite entry point for attackers precisely because it sits at the network edge, brokering remote access for entire organizations. Flaws here tend to draw fast attention from both defenders and opportunistic scanners.

What CVE-2026-19490 actually does

Classified under CWE-288 (improper authentication), the bug allows an attacker to “circumvent authentication controls” on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN or RDP Proxy, or configured as an AAA virtual server. In plain terms: on a vulnerable, unpatched build, someone attempting to reach an organization’s internal network or remote desktop infrastructure through NetScaler may not need valid credentials at all.

Exploitability depends on the specific build in use. On newer builds — 14.1-43.56 and above, or 13.1-61.28 and above — the flaw requires the appliance to have SAML action configured before it’s exploitable. On earlier builds, any Gateway or AAA virtual server configuration is enough to be at risk, which broadens the exposed population considerably.

The second bug: a denial-of-service trigger

CVE-2026-19489, classified under CWE-119 (memory overflow), is triggered when the SIP ALG (Session Initiation Protocol Application Layer Gateway) feature is enabled within a Large Scale NAT (LSN) group configuration. Successful exploitation results in unpredictable device behavior or a denial-of-service condition — less catastrophic than an authentication bypass, but still capable of knocking critical remote-access infrastructure offline.

Who’s affected

The vulnerable population spans both current release branches:

  • NetScaler ADC and Gateway 14.1, before build 73.32
  • NetScaler ADC and Gateway 13.1, before build 63.21
  • FIPS and NDcPP variants of both release lines
  • Secure Private Access Hybrid deployments that use customer-managed NetScaler instances

Fixed builds are 14.1-73.32 and 13.1-63.21 (and their corresponding FIPS/NDcPP releases) or later.

Is it being exploited yet?

There’s no confirmed evidence of in-the-wild exploitation at the time of disclosure. That said, NetScaler’s history is not reassuring on this front — previous high-severity flaws in the product line, including the notorious “CitrixBleed” bug, went from patch release to mass exploitation within days once technical details and proof-of-concept code began circulating. Security teams should assume the same window applies here.

What administrators should do now

  • Identify every NetScaler ADC/Gateway instance in the environment and check its build number against the fixed versions above
  • Review configuration files for the specific risk conditions — SAML action configuration on newer builds, or LSN groups with SIP ALG enabled
  • Prioritize the update as an urgent security action rather than folding it into routine patch cycles
  • After patching, review access and authentication logs for anomalies predating the fix, in case exploitation already occurred

Given NetScaler’s role as a remote-access chokepoint and the near-maximum severity score attached to the authentication-bypass flaw, organizations running affected builds should treat this as a same-week, not same-quarter, priority.

How NetScaler flaws typically play out

NetScaler occupies a specific place in enterprise networks: it is one of the few devices designed to be reachable from the open internet, brokering remote access for employees and partners while everything behind it stays private. That position is exactly what makes flaws in the product so consequential. The 2023 CitrixBleed vulnerability, for example, went from disclosure to mass exploitation by ransomware affiliates within roughly a week, compromising thousands of appliances before many organizations had finished testing the patch. Security researchers tracking this new pair of bugs expect a similar timeline: once proof-of-concept exploit code for CVE-2026-19490 begins circulating in security research circles or underground forums, scanning activity against internet-facing NetScaler appliances tends to spike almost immediately.

That history is part of why Citrix and independent researchers are urging administrators not to wait for a confirmed in-the-wild exploitation report before patching. By the time exploitation is publicly confirmed, a meaningful share of vulnerable appliances have often already been compromised.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely, use the discussion on Forum.

>> forum community

Comments

Leave a Reply