{"id":242979,"date":"2026-08-21T01:23:08","date_gmt":"2026-08-21T06:23:08","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible"},"modified":"2026-08-21T01:23:08","modified_gmt":"2026-08-21T06:23:08","slug":"citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible","title":{"rendered":"Citrix urges admins to patch new NetScaler flaws as soon as possible"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible.jpg\"><\/a><\/p>\n<p>Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.<\/p>\n<p>The most severe of the two, tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-19490\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026\u201319490<\/a>, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured.<\/p>\n<p>Admins can check if an appliance is vulnerable to attacks targeting CVE-2026\u201319490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction.<span style=\"font-size: 1.3em;\">\u2022<\/span> string and Auth or VPN vserver (\u2018add authentication vserver.*\u2019 and \u2018add vpn vserver.*\u2019) strings.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026\u201319490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1492],"tags":[],"class_list":["post-242979","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242979","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242979"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242979\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242979"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242979"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242979"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}