Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials

Cloud Software program Group has issued a crucial safety bulletin warning clients of two severe vulnerabilities affecting NetScaler ADC (previously Citrix ADC) and NetScaler Gateway (previously Citrix Gateway).

Tracked as CVE-2026-19489 and CVE-2026-19490, the failings might enable attackers to set off denial-of-service conditions or bypass authentication completely on unpatched home equipment, placing enterprise distant entry infrastructure at important danger.

Important Citrix NetScaler Vulnerability

The extra extreme of the 2, CVE-2026-19490, carries a CVSS v4.0 base rating of 9.3 and is assessed underneath CWE-288, Authentication Bypass Utilizing an Alternate Path. This flaw permits an attacker to bypass authentication controls on NetScaler home equipment configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA digital server.

The exploitability depends upon the particular software program construct in use. On NetScaler 14.1-43.56 and later, in addition to 13.1-61.28 and later, the vulnerability is exploitable solely when the equipment is configured with a SAML motion.

On earlier builds, nonetheless, any Gateway or AAA vserver configuration is enough to reveal the flaw, making a broader set of deployments susceptible. On condition that authentication gateways are the first management level for distant entry, profitable exploitation might grant attackers unauthorized entry into company networks with out legitimate credentials.

The second vulnerability, CVE-2026-19489, scores 8.8 on the CVSS v4.0 scale and stems from a reminiscence overflow subject tied to CWE-119, Improper Restriction of Operations inside the Bounds of a Reminiscence Buffer.

This bug is triggered when SIP ALG, the Session Initiation Protocol Application Layer Gateway, is enabled inside a Giant Scale NAT (LSN) group configuration. Exploitation can result in unpredictable equipment conduct or a full denial-of-service outage, disrupting crucial community providers that rely upon the NetScaler for visitors administration and NAT translation.

The vulnerabilities have an effect on NetScaler ADC and NetScaler Gateway model 14.1 earlier than construct 73.32, model 13.1 earlier than construct 63.21, in addition to the FIPS and NDcPP variants of those releases.

Notably, Safe Personal Entry Hybrid deployments that depend on customer-managed NetScaler cases are additionally uncovered and require the identical upgrades, although Cloud Software program Group has already patched its cloud-managed providers and Adaptive Authentication choices.

Directors can examine publicity by reviewing their NetScaler configuration recordsdata for particular command strings. For CVE-2026-19489, trying to find LSN group entries containing SIP ALG settings will affirm the precondition. For CVE-2026-19490, checking for SAML motion configurations or present authentication and VPN vserver entries will reveal whether or not the equipment meets the factors for exploitation.

Cloud Software Group is urging all clients to improve instantly to NetScaler ADC and Gateway 14.1-73.32 or later, 13.1-63.21 or later, or the corresponding FIPS and NDcPP builds.

Given the network-facing nature of those home equipment and the low complexity required for exploitation, safety groups ought to deal with patching as an pressing precedence fairly than a routine upkeep job.

The vulnerabilities have been responsibly disclosed by Samarth Vashisht of JPMorgan Chase’s penetration testing workforce, underscoring the worth of coordinated vulnerability analysis in defending broadly deployed enterprise infrastructure.

Organizations nonetheless working susceptible builds ought to assume elevated danger of focused scanning as soon as technical particulars flow into extra broadly, a sample traditionally seen with prior Citrix and NetScaler flaws.

Forestall incidents on account of gradual investigations. Energy your Tier 1 with menace intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *