Citrix Releases Critical Security Updates for Netscaler ADC and Gateway

Citrix has announced the release of crucial security updates aimed at addressing multiple vulnerabilities in its Netscaler ADC and Netscaler Gateway products. These flaws, if left unpatched, could potentially allow unauthorized individuals to bypass authentication mechanisms and gain illicit access to affected systems.

The company detailed that the most serious vulnerability enables attackers to circumvent established authentication processes under certain conditions. According to Citrix, the specific flaw has been assigned the identifier CVE-2026-19490 and is considered critical, with a CVSS 4 score of 9.3. The issue arises when particular configurations are in place for remote access, especially in scenarios where SAML authentication is used for identity verification. However, Citrix has not disclosed the precise methods by which this authentication bypass could be exploited, citing security reasons.

In addition to the critical vulnerability, Citrix has addressed another significant security issue related to a memory overflow. This flaw, classified as high risk (CVE-2026-19489, CVSS 4 score of 8.8), could result in unpredictable system behavior or potentially lead to Denial-of-Service (DoS) situations. The vulnerability is specifically linked to the activation of SIP ALG within large-scale NAT group configurations. While there is no confirmation regarding the possibility of executing arbitrary code through this flaw, the risk remains substantial for organizations utilizing the affected features.

The identified vulnerabilities impact Citrix Netscaler ADC and Netscaler Gateway installations running versions prior to 14.1-73.32 and 13.1-63.21. Updates are also available for NetScaler ADC FIPS, with version 14.1-73.32 FIPS and NetScaler ADC FIPS and NDcPP from 13.1-37.277 onwards reportedly free from these issues. Citrix has confirmed that its managed cloud instances have already been updated, but organizations operating self-managed installations are strongly advised to apply the latest security patches as soon as possible to mitigate exposure.

These recent updates follow previous disclosures of major vulnerabilities in Citrix's Netscaler ADC and Gateway solutions, where attackers were able to exploit flaws to disrupt vulnerable instances. The recurring nature of such security concerns highlights the importance of maintaining up-to-date software and promptly addressing any identified vulnerabilities, particularly in systems critical to remote access and network security.

Citrix is urging administrators to review their current deployments, verify whether their versions are affected, and implement the recommended updates without delay. By taking swift action, organizations can reduce the risk of exploitation and ensure continued protection of their networks and sensitive data.

For additional details on the updates and guidance for implementing the patches, Citrix refers users to its official security advisory and support resources. Staying vigilant and proactive in applying security fixes remains essential to safeguarding enterprise IT infrastructures from emerging threats.