CVE Tools

Citrix urges admins to patch new NetScaler flaws as soon as possible

BleepingComputerBy Sergiu Gatlan

PatchNetScaler ADCNetScaler Gateway

Our summary

Citrix has issued a security update addressing two newly disclosed vulnerabilities in its NetScaler ADC and NetScaler Gateway products. The most severe flaw, CVE-2026-19490, allows unauthenticated remote attackers to bypass authentication mechanisms under specific configuration conditions, while CVE-2026-19489 permits denial-of-service attacks via a memory overflow when SIP ALG is enabled. Although there is no evidence of active exploitation yet, the vendor strongly recommends that administrators apply the relevant patches immediately to secure their environments.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store