CVE Tools
Back to feed
Patch released NetScaler ADC auth-bypass NetScaler Gateway Citrix web-app

Citrix urges admins to patch new NetScaler flaws as soon as possible

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Citrix has issued a security update addressing two newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products. The most severe flaw, CVE-2026-19490, allows unauthenticated remote attackers to bypass authentication mechanisms under specific configuration conditions, while CVE-2026-19489 permits denial-of-service attacks via a memory overflow when SIP ALG is enabled. Although there is no evidence of active exploitation yet, the vendor strongly recommends that administrators apply the relevant patches immediately to secure their environments.