Citrix has urged customers to review and patch affected NetScaler deployments after disclosing two vulnerabilities in NetScaler Gateway and NetScaler ADC, according to BleepingComputer. The affected products include NetScaler Gateway secure remote access systems and NetScaler ADC networking appliances. The higher-impact issue is CVE-2026-19490, which BleepingComputer describes as an authentication bypass that can be triggered remotely by attackers without privileges. The exposure is configuration-dependent: the report says it applies when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy scenarios, depending on firmware version and whether SAML Action is configured. For administrators, the immediate task is not only version checking but configuration checking. BleepingComputer reports that Citrix advised teams to inspect NetScaler configurations for SAML action configuration strings and authentication or VPN virtual-server strings to determine whether CVE-2026-19490 applies to their environment. The second flaw, CVE-2026-19489, is described as a high-severity memory overflow issue. According to BleepingComputer, unauthenticated remote attackers could abuse it for denial-of-service attacks when Session Initiation Protocol Application Layer Gateway, or SIP ALG, is enabled on a large-scale NAT group configuration. Security teams can check for the relevant precondition by looking for the large-scale NAT group configuration string tied to SIP ALG, the report says. BleepingComputer says Citrix's bulletin applies to supported customer-managed NetScaler ADC and NetScaler Gateway versions, including certain FIPS and NDcPP builds. It also says SecurAccess ZTNA Hybrid deployments, formerly Secure Private Access Hybrid, are affected when they use customer-managed NetScaler instances and should be moved to recommended builds. The report says the two new vulnerabilities have not been flagged as exploited in attacks. Still, the urgency reflects NetScaler's recent history: BleepingComputer notes that Citrix urged administrators to patch CVE-2026-3055 and CVE-2026-4368 on March 23, shortly before attackers began exploiting them in the wild. CISA later added CVE-2026-3055 to its Known Exploited Vulnerabilities catalog on March 30 and ordered federal agencies to secure vulnerable Citrix appliances within three days. Exposure is not limited to a small installed base. BleepingComputer reports that the ShadowServer Foundation tracks more than 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances exposed online. The same report cautions that ShadowServer does not say how many of those are honeypots or how many are actually vulnerable to CVE-2026-19489 or CVE-2026-19490. Who benefits: Enterprises that rapidly inventory customer-managed NetScaler ADC and Gateway deployments, confirm the relevant configurations, and move affected systems to recommended builds reduce their exposure window. Security teams with accurate appliance configuration data are best positioned to act quickly. Who's exposed: Organizations running supported customer-managed NetScaler ADC or Gateway appliances may be exposed if their configurations meet the CVE-specific preconditions. SecurAccess ZTNA Hybrid deployments using customer-managed NetScaler instances are also in scope, according to BleepingComputer's account of Citrix's bulletin.