Citrix NetScaler Authentication Bypass and DoS vulnerabilities require immediate patching
Citrix has issued an urgent advisory warning customers to patch two newly disclosed vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. The most severe vulnerability, CVE-2026-19490, enables unauthenticated authentication bypass under specific configurations, potentially allowing remote attackers to gain unauthorized access to exposed services. A second vulnerability, CVE-2026-19489, could enable unauthenticated attackers to trigger denial-of-service (DoS) conditions.