“There are no public indicators that these two new flaws are being exploited at the moment, but that is likely to change within hours, given the ability of threat actors to weaponize the update patch to discern the exploit details,” he said, given that a CVSS 9.3 authentication bypass flaw on a NetScaler Gateway or AAA server is precisely the kind of vulnerability defenders do not want sitting on an internet-facing boundary, because a successful exploit could allow unauthorized access to resources behind the gateway, followed by credential or session abuse, reconnaissance, lateral movement and ultimately data theft or broader compromise.
The second major hole flagged by Citrix, CVE-2026-19489, with an 8.8 CVSS score, is less of a concern but still worrisome, he noted.
“It requires SIP ALG to be enabled on a large-scale NAT group, so the vulnerable population should be considerably smaller,” Wilkes said. “Nevertheless, a remotely triggerable memory overflow capable of producing unpredictable behavior or denial of service is consequential on infrastructure whose purpose is keeping applications and remote users connected. An attacker does not necessarily need to steal data for an attack to be damaging: repeatedly destabilizing or crashing an ADC or gateway can interrupt VPN access, customer-facing applications and other dependent services at precisely the moment an organization needs them.”


