Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Harry and Meghan’s security funding on UK return is private matter, Burnham says | Prince Harry

    August 20, 2026

    Racism and sexism have become normalised in Britain, says equalities minister | Bridget Phillipson

    August 20, 2026

    Harvest price hike hits business with 1500% increase in bills

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Harry and Meghan’s security funding on UK return is private matter, Burnham says | Prince Harry
    • Racism and sexism have become normalised in Britain, says equalities minister | Bridget Phillipson
    • Harvest price hike hits business with 1500% increase in bills
    • Agentic AI Presents New Insider Threat Model for Orgs
    • Nearly 1 in 5 crypto spot trades now happen on DEXs as centralized exchange volume collapses
    • Notes from Illinois’ Virtual Power Plant Frontier
    • MacGregor’s 165-ton crane ordered for Jan De Nul newbuild
    • Despite SafeSport Ban, Girls Volleyball Coach Ryan Richardson Continues to Work With Kids — ProPublica
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Citrix urges admins to patch new NetScaler flaws as soon as possible

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

    The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.

    Admins can check if an appliance is vulnerable to attacks targeting CVE-2026-19490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction .*) string and Auth or VPN vserver (‘add authentication vserver .*’ and ‘add vpn vserver .*’) strings.

    image

    The second, a high-severity memory overflow security flaw tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration.

    Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the “add lsn group.*sipalg.*” string.

    Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to:

    • NetScaler ADC and NetScaler Gateway 14.1-73.32 or later,
    • NetScaler ADC and NetScaler Gateway 13.1-63.21 or later,
    • NetScaler ADC FIPS 14.1-73.32 FIPS or later,
    • or NetScaler ADC FIPS and NDcPP 13.1-37.277 or later, as applicable

    “We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Citrix warned on Wednesday.

    “The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds.”

    While these security flaws have not been flagged as exploited in attacks, Citrix urged admins to patch two other NetScaler vulnerabilities (CVE-2026-3055 and CVE-2026-4368) on March 23, just days before attackers began abusing them in the wild.

    CISA added the CVE-2026-3055 vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days.

    Over the last five years, the U.S. cybersecurity agency has flagged 22 Citrix vulnerabilities as exploited in the wild, six of them also abused in ransomware attacks.

    The ShadowServer Foundation now tracks over 22,000 NetScaler ADC and nearly 1,800 NetScaler Gateway instances exposed online. However, it does not provide information on the number of honeypots or how many may be vulnerable to attacks targeting CVE-2026-19489 and CVE-2026-19490.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    admins Citrix flaws NetScaler patch urges
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Agentic AI Presents New Insider Threat Model for Orgs

    CISA warns of hackers exploiting critical MLflow vulnerability

    OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

    Critical Zimbra RCE flaw now actively exploited in attacks

    Hackers compromise 14,500 Dahua web cameras in 35-day campaign

    Microsoft says August Windows updates may cause gaming issues

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Harry and Meghan’s security funding on UK return is private matter, Burnham says | Prince Harry

    August 20, 2026

    Racism and sexism have become normalised in Britain, says equalities minister | Bridget Phillipson

    August 20, 2026

    Harvest price hike hits business with 1500% increase in bills

    August 20, 2026

    Agentic AI Presents New Insider Threat Model for Orgs

    August 20, 2026
    Latest Posts

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    July 28, 2026

    OpenAI’s biggest threat may just be open AI

    July 28, 2026

    6 Takeaways From Michigan’s Senate Debate Between Abdul El-Sayed and Haley Stevens

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Harry and Meghan’s security funding on UK return is private matter, Burnham says | Prince Harry

    August 20, 2026

    Racism and sexism have become normalised in Britain, says equalities minister | Bridget Phillipson

    August 20, 2026

    Harvest price hike hits business with 1500% increase in bills

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.