
Work Here?
Company Historically Provides H1B Sponsorship
Citrix focuses on remote access and digital workspace software that lets people securely access apps and data from anywhere, on any device. Its tools deliver app delivery, secure access, and centralized workspace management so employees can stay productive regardless of location or network. The products work by providing remote connectivity, virtualization and app delivery layers, and management features through licenses, subscriptions, and support services, all under the Cloud Software Group umbrella. Compared with competitors, Citrix emphasizes broad reach across large enterprises and small businesses with a strong focus on secure, reliable access to applications and data, and comprehensive workspace management across diverse networks and devices. The company’s goal is to help organizations maintain operational efficiency and security in a mobile and distributed work environment by ensuring apps stay available, data remains protected, and employees remain productive.
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Debt Financing
Total Funding
$1.8B
Headquarters
Fort Lauderdale, Florida
Founded
1989
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$1.8B
Above
Industry Average
Funded Over
7 Rounds
Parental Leave
Citrix has completed its acquisition of Numecent, the company behind Cloudpaging and Cloudpager technologies for Windows application management. Cloudpaging packages Windows applications into isolated containers that can be streamed to endpoints without traditional installation, whilst Cloudpager provides cloud-based management across physical and virtual Windows environments. The acquisition expands Citrix DaaS capabilities for application delivery. The technology addresses common enterprise IT challenges including bloated desktop images, application conflicts, and lengthy ransomware recovery times. Citrix customers will benefit from lower desktop management costs, faster application recovery after incidents, reduced application conflicts, and centralised management across Windows environments. The acquisition builds on an integration launched in April that enabled administrators to publish Cloudpaging containers through Citrix workflows. Citrix plans to further integrate both products into its platform whilst maintaining support for physical Windows desktops outside DaaS environments.
Citrix acquires Numecent to simplify and broaden application management and delivery capabilities across Windows environments. Citrix announced it has completed the acquisition of Numecent, the company behind two complementary products: Cloudpaging, a patented technology that packages Windows applications into isolated application containers independent of the underlying operating system, and Cloudpager, a cloud management console that provisions, updates, rolls back, removes and meters applications across physical and virtual Windows endpoints. The acquisition expands Citrix DaaS capabilities for cloud-based application delivery across Windows environments, helping reduce the complexity and cost of traditional app packaging and image management. Unlike solutions tied to virtual desktops, Numecent's technology extends application delivery across physical and virtual Windows environments, helping organizations simplify application management at enterprise scale. Numecent modernizes enterprise application delivery Enterprise IT teams managing physical and virtual Windows environments face a persistent set of challenges: bloated desktop images that take weeks to update, application conflicts that break production environments and ransomware incidents that can take weeks to recover from. Numecent's technology is designed to address all three. Cloudpaging packages Windows applications into isolated containers and streams them to Windows endpoints on demand, without traditional installation or changes to the base image. Applications behave as if natively installed. Cloudpager provides cloud-based management to assign applications to users and devices, push updates, roll back releases, recall licenses and meter usage across Windows endpoints from one console. This acquisition builds upon the two companies' work to integrate the Cloudpager with Citrix DaaS, following an integration launched in April enabling administrators to natively publish and manage Cloudpaging application containers through familiar Citrix workflows. What this means for Citrix customers With the acquisition, Citrix customers will benefit from: · Lower desktop-management costs: Separating applications from the image can reduce the size and number of images IT maintains and shorten application update cycles. · Rapid application recovery: After ransomware or a site failure, IT can rebuild a clean environment and quickly repopulate applications from the cloud, cutting Recovery Time Objectives and the revenue loss and regulatory exposure of an extended outage. · Reduced application conflicts: Legacy and modern applications can run side by side, reducing application conflicts and associated troubleshooting. · Less application repackaging: A single container can provide greater application compatibility across operating system versions and physical and virtual Windows environments, reducing the need for repackaging. · Lower administrative overhead and greater control and visibility into software usage: IT can manage applications across virtual and physical Windows environments from one console and meter software usage and recall unused licenses. · Enable DevOps automation workflows: IT and DevOps teams can leverage containerization to help automate application packaging and control deployment to improve speed and consistency, reduce manual steps and support a more secure environment. "Enterprise customers have told us for years that application management is one of the most painful parts of running a Windows environment," said Shawn Bass, senior vice president and general manager of Citrix DaaS. "Numecent has solved this in a genuinely elegant way. By bringing Cloudpaging and Cloudpager into Citrix, we can make this capability native to every DaaS and physical desktop deployment so IT teams get back the time they spend wrestling with images and app conflicts." "Joining Citrix accelerates everything we set out to do," said Arthur Hitomi, CEO of Numecent. "Our Cloudpaging technology was built for exactly the kind of complex, high-scale environments Citrix serves. Together, we can bring app-centric resilience to enterprise desktops worldwide." Citrix plans to further integrate Cloudpaging and Cloudpager into the Citrix platform while continuing support for physical Windows desktops and laptops outside Citrix DaaS environments. This will give customers a consistent application delivery model across virtual and physical Windows environments. Existing Numecent customers will continue to receive support throughout the transition. Existing Citrix customers should contact their account teams for more information. David Marshall is the founder of VMblog.com, one of the industry's longest-running independent publications covering modern data center technologies. What began as a focus on virtualization and cloud computing has expanded to cover the full spectrum of enterprise IT, including AI, security, and DevOps, making VMblog a trusted destination for vendor news, technology analysis, and industry commentary.Beyond publishing, David has spent his career at the intersection of technology and business, inventing, marketing, and launching a number of successful software companies and products, and building a reputation as a skilled marketing executive in the enterprise IT space.David is also a published author, having written two well-regarded books on virtualization and served as technical editor for two "For Dummies" titles covering virtualization and cloud computing. He co-founded CloudCow.com, a publication focused on cloud computing, and has been named a VMware vExpert every year since 2009, one of the longest continuous honoree streaks in the program's history.Connect with David on LinkedIn: https://www.linkedin.com/in/davidmarshall/
Citrix NetScaler flaw under active attack - CISA says that 'dos only' bug is actually a backdoor. York Computer - 2026-08-31 A Citrix NetScaler flaw that Citrix originally labeled as a harmless denial-of-service bug in June has turned out to be much worse - attackers are using it to drop web shells and take over the appliances that sit at the edge of many small-business networks. CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26 and ordered federal agencies to remediate by August 29. If your business (or your landlord, vendor, or accountant) uses a NetScaler ADC or Gateway to publish remote access, you need to know where you stand this week. What actually happened. Citrix issued a patch on June 30 for a memory-buffer flaw in NetScaler ADC and NetScaler Gateway. At the time, Citrix rated the June 30 patch as denial-of-service only, not remote code execution, but attackers have since been dropping webshells and running discovery commands on compromised appliances, and federal agencies were given until August 29 to remediate under CISA's directive. The re-evaluation wasn't theoretical. CISA added the Citrix NetScaler ADC and NetScaler Gateway vulnerability to its Known Exploited Vulnerabilities catalog citing evidence of active exploitation, and researchers have published details of how the attacks look on the wire. Attackers were dropping web shells named 'x.php' and 'z.php' and running discovery commands like 'id' and 'echo,' with 36 exploitation attempts detected over 12 days from 12 unique attacker IP addresses spanning Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the U.S., and Vietnam. In plain English: a bug the vendor said would only crash the box is being used to plant a hidden control panel on it. Why a small business should care. NetScaler ADC and NetScaler Gateway are the boxes that publish remote desktop, Citrix apps, VPN portals, and single sign-on to the internet. A lot of small and mid-sized organizations don't run one directly - but their bank, their law firm, their EHR vendor, their property manager, or their outsourced HR platform very likely does. When one of those appliances gets a web shell dropped on it, the attacker is now sitting inside a trusted network with credentials to move sideways. This isn't a hypothetical Pennsylvania problem either. Researchers previously tied the Pennsylvania Office of Attorney General ransomware breach to internet-exposed instances of Citrix NetScaler vulnerable to CVE-2025-5777, known as Citrix Bleed 2, with two internet-exposed NetScaler devices tied to the Office of the Attorney General later removed from the internet. Same product family, same attack pattern, same outcome - encrypted files and stolen data. What your managed-IT provider should be doing right now. If you have an MSP or an in-house IT person, this week's checklist is short and specific: 1. Confirm whether any NetScaler ADC or NetScaler Gateway appliance sits on your perimeter - including at parent companies, sister offices, or hosted vendors that terminate on your network. 2. Apply the Citrix fix for CVE-2026-8452 and verify the build number, not just the update log. 3. Hunt for the indicators of compromise - files named x.php or z.php in web-accessible paths, unexpected outbound connections, and new admin sessions from foreign IP ranges. 4. Rotate NetScaler admin credentials, session tokens, and any AD service accounts the appliance uses. A patch does not evict an attacker who already got in before the patch was applied. Edge-device patching and 24/7 monitoring for exactly this kind of appliance are core to York Computer's managed IT services. If your business is running lean and you already have an internal tech handling day-to-day tickets, its co-managed IT support is designed to add the after-hours vulnerability response and threat-hunting muscle that KEV entries like this one actually require. The bigger pattern. This is the second Citrix NetScaler bug in roughly a year that started life as a low-severity advisory and ended up on CISA's exploited list. The lesson for small businesses isn't 'stop using Citrix' - it's that vendor severity ratings are a starting point, not a verdict. A responsible IT provider treats every edge device (NetScaler, Fortinet, SonicWall, Cisco ASA, Ivanti) as high-risk by default and patches on the vendor's timeline, not on 'York Computer'll get to it next quarter.' What York businesses should do. York County businesses that rely on hosted portals from Harrisburg-area law firms, benefits administrators, or regional healthcare networks should ask those vendors this week whether they run NetScaler and whether CVE-2026-8452 has been patched. The Pennsylvania AG breach last year showed how one unpatched appliance at a trusted partner can spill data statewide. Sources. Worried whether your business is exposed to this? Talk to York Computer. Managed IT & cybersecurity for York County small businesses.
You have days, not weeks: patching the CVSS 9.3 NetScaler auth bypass (CVE-2026-19490). The NetScaler auth bypass CVE-2026-19490 is being treated as a simple patch-now advisory, but for UK SMEs the real danger is the box nobody knew they had. Here's how to find it before an attacker does. A Citrix NetScaler appliance sits at the edge of thousands of UK company networks, quietly doing its job: load balancing traffic, terminating VPN sessions, brokering logins for remote workers. Most of the people who rely on it every day have never heard the word "NetScaler". That anonymity is exactly what makes CVE-2026-19490 so dangerous. This is a CVSS 9.3 authentication bypass. In plain terms, an attacker can reach the appliance and walk past the login it is supposed to enforce. No stolen credentials, no phishing, no clever social engineering. On a vulnerable box exposed to the internet, that gets an intruder a foothold on the very device that guards your remote access. Citrix has released fixed firmware and, as usual with these edge-device flaws, exploitation started in the wild before most organisations had finished reading the advisory. The standard coverage says "patch now". That advice is correct and also nearly useless, because it assumes you know where all your NetScaler appliances are. For a lot of UK SMEs, that assumption is wrong. The box nobody owns. Here is how these appliances end up invisible. A NetScaler gets bought and racked as part of a networking project - maybe when the company moved to a new office, maybe when it rolled out remote working during a growth spurt. The network team or a contractor set it up, pointed the firewall at it, and moved on. It works, so nobody touches it. Fast forward two years. The person who configured it has left. The vulnerability scanner your MSP runs is authenticated against Windows and Linux servers, but the NetScaler was never added to the scope because nobody remembered it was a separate device. It doesn't appear in the CMDB because the CMDB was built from the domain and this thing isn't domain-joined. It doesn't show up in your endpoint management console because you can't install an agent on it. So when the advisory lands, the honest answer to "are we affected?" is "we don't know". And "we don't know" is the answer that gets companies breached. Cloudworks saw this exact pattern with the Citrix Bleed vulnerabilities a couple of years back. The organisations that got hurt weren't the ones running old firmware on purpose. They were the ones who genuinely didn't realise they still had an internet-facing NetScaler at all, or thought a decommissioned one had actually been unplugged. The device outlived the institutional memory of it. Reframe it: inventory first, patching second. Treat CVE-2026-19490 as an asset discovery problem before you treat it as a patching problem. If you're an MSP, or an internal IT lead managing your own estate, work through this order. 1. Find every appliance from the outside in. Attackers scan the whole IPv4 internet for exposed NetScaler management and gateway interfaces daily. You should look at your own perimeter the same way. Enumerate every public IP your clients own - the ranges from their ISP, any cloud provider allocations, and blocks assigned to old contracts nobody cancelled. Then check what's listening. NetScaler gateway and management pages have recognisable fingerprints. External attack surface tools like Shodan or Censys will often flag a Citrix ADC/NetScaler by its response headers and login page. If you have a proper external attack surface management service, run it against the full IP inventory and filter for Citrix. If you don't, a targeted scan of ports 443 and the management ports across your clients' ranges will surface most of them. 2. Cross-check the network side. Ask the network team - or the person who holds that role now - for a list of appliances at each site, including anything in a comms cupboard that isn't a switch or a firewall. Compare that against your CMDB. Every gap between the two lists is a candidate for exactly the invisible-box problem described above. 3. Check what was supposedly decommissioned. A device that was "switched off" but never physically removed and never had its firewall rule deleted is the worst of both worlds: reachable and forgotten. Confirm decommissioned appliances are actually powered down or unracked, and that the NAT or port-forward rules pointing at them are gone. Confirm exposure, don't assume it. Once you've found the appliances, don't panic-patch blindly and don't wave it away either. Confirm whether each one is genuinely exposed to this specific flaw. Check the SAML precondition. CVE-2026-19490, like several recent NetScaler bypasses, only bites when the appliance is configured in a particular way - in this case relating to SAML authentication being enabled on the gateway or authentication virtual server. If SAML auth isn't configured, the exploitable path may not be present. This matters because it tells you which boxes are genuinely on fire and which can wait for the maintenance window. Don't take "we don't use SAML" on trust. Log into each appliance and verify the running configuration. Check the authentication policies bound to your gateway and AAA virtual servers, and look for SAML action and policy objects actually in use. A device can have SAML configured from a project that was abandoned halfway through. Verify the live config, not the intention. Confirm the fixed version - precisely. Citrix firmware version strings are fiddly, and "we're on a recent build" is not a version number. Pull the exact firmware build from each appliance and match it against the fixed builds named in the Citrix advisory for your specific release train. NetScaler maintains several parallel branches, and the fix appears as a different build number in each. Being patched on one branch tells you nothing about a box on another. Write down the actual build you confirmed, per device, with the date. While you're in there, remember that many NetScaler advisories recommend killing existing sessions after patching, because an attacker who got in before the fix can persist through a stolen session token. Follow the advisory's post-patch steps - terminating active ICA and PCoIP sessions and rotating relevant secrets - rather than assuming the firmware update alone evicts anyone already inside. A tight playbook for MSPs. If you manage multiple clients, run this as a coordinated sweep rather than ticket by ticket: * Build a master list of all public IP ranges across every client. * Run external discovery to fingerprint every Citrix NetScaler on those ranges. * Reconcile discovered appliances against each client's CMDB; flag every unknown. * For each appliance: confirm the exact firmware build, check whether SAML auth is configured, and record both. * Prioritise: SAML-enabled and internet-facing goes first, today. Everything else follows in a controlled window. * Patch to the confirmed fixed build for that release branch, then run the advisory's session-termination and secret-rotation steps. * Update the CMDB so the box is never invisible again. The lesson that outlasts this CVE. CVE-2026-19490 will be patched and forgotten within a month. The underlying weakness - that your most exposed devices are the ones your security tooling can't see - will still be there for the next one. Edge appliances from Citrix, Fortinet, Ivanti and others have become a favourite target precisely because they sit outside normal asset management. So do the patching now, because you genuinely have days not weeks. But use this scramble to fix the thing that made it a scramble: get every internet-facing appliance into a single inventory, with an owner, a firmware version, and a place in your scanning scope. If you can't answer "what edge devices do we run and what version are they on?" in five minutes, that's the real vulnerability - and no patch fixes it. If you're not sure what's sitting at the edge of your network, that's exactly the conversation to have with Cloudworks before the next advisory lands.
CISA flags active exploitation of Citrix NetScaler flaw as six vulnerabilities join Exploited catalog. What happened. CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, with the most significant being CVE-2026-8452, a memory overflow flaw in Citrix NetScaler ADC and NetScaler Gateway rated 8.8 on the CVSS scale. Citrix disclosed the flaw at the end of June and described the impact at the time as limited to denial-of-service conditions on appliances configured with Gateway VPN or AAA virtual servers. Independent research from watchTowr published in August found successful exploitation also grants remote code execution as root on unpatched instances, a substantially more severe outcome than the original advisory suggested. Telemetry gathered over the past 12 days recorded 36 exploitation attempts originating from 12 attacker-controlled IP addresses spread across ten countries, including Russia, Germany, and Switzerland. Federal civilian agencies face an August 29 remediation deadline. Why this matters for Canadian organizations. NetScaler appliances sit at the network perimeter for many Canadian enterprises and government departments, functioning as VPN gateways and load balancers guarding access into internal systems. Appliances performing this role represent high-value initial access points for attackers, since a single compromised gateway often opens a path into an entire internal network. The revision from a denial-of-service-only assessment in June to confirmed remote code execution in August is a reminder: early vendor severity ratings sometimes understate real-world risk once independent researchers examine an exploit chain in depth. Under OSFI B-13, regulated entities operating internet-facing remote access infrastructure carry direct responsibility for timely patching of critical vulnerabilities, and any confirmed compromise involving customer data triggers PIPEDA breach notification obligations. What to do. Organizations running NetScaler ADC or Gateway should apply Citrix's June patch immediately if this has not already happened, treating the update as critical rather than routine given the confirmed root-level RCE path. Security teams should specifically review Gateway VPN and AAA virtual server configurations, the deployment modes named as vulnerable in the original advisory. Network defenders should monitor for connection attempts from the attacker infrastructure identified in CISA's telemetry and review authentication logs for signs of prior exploitation extending back to late June. Additional technical detail is available from Help Net Security. Enjoy this article? Don't forget to share.
Find jobs on Simplify and start your career today
Industries
Enterprise Software
Cybersecurity
Company Size
1,001-5,000
Company Stage
Debt Financing
Total Funding
$1.8B
Headquarters
Fort Lauderdale, Florida
Founded
1989
Find jobs on Simplify and start your career today