CITRIX has released patches for two vulnerabilities in its NetScaler ADC and NetScaler Gateway, one of which (CVE-2026-19490) is a critical authentication bypass issue with a CVSS score of 9.3. This flaw allows remote attackers to exploit the system without user interaction, making it a significant security risk. The affected versions include several iterations of NetScaler, and the patches are available in specific builds.
Rapid7 emphasizes the importance of immediate patching, as the critical role of NetScaler in enterprise networks makes it a prime target for threats. There are currently no known active exploits, but exploitation is likely due to the system's visibility.