T

Threats

Citrix NetScaler ADC and Gateway Critical Vulnerabilities

Overview

Citrix has released security updates for two vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-19490 is a critical authentication-bypass vulnerability with a CVSS v4.0 score of 9.3. CVE-2026-19489 is a high-severity memory-overflow vulnerability with a CVSS v4.0 score of 8.8.

Both flaws affect customer-managed appliances only when their stated configuration preconditions are present. As these products commonly operate at the network edge, Australian organisations should assess exposure and install the relevant fixed build as soon as practicable.


Affected Versions

The following supported releases are affected when the relevant CVE preconditions described below are met.

NetScaler ADC and NetScaler Gateway 14.1

NetScaler ADC and NetScaler Gateway 13.1

NetScaler ADC FIPS 14.1

NetScaler ADC FIPS and NDcPP 13.1

Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must upgrade those instances to the recommended builds. The bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have received the necessary software updates from Cloud Software Group.


Vulnerability Breakdown

CVE-2026-19490 - Authentication Bypass Using an Alternate Path

  • Severity: Critical

  • CVSS: 9.3, CVSS v4.0

  • Description: An alternate authentication path can bypass expected authentication controls when an affected appliance meets specified Gateway, AAA virtual server or SAML configuration requirements.

  • Impact: Successful exploitation may allow unauthorised access and compromise the confidentiality, integrity and availability of affected systems.

  • Conditions:

    • 14.1-43.56 or later requires a SAML action and a Gateway or AAA virtual server configuration.

    • 14.1-66.68-FIPS or later requires a SAML action and a Gateway or AAA virtual server configuration.

    • 14.1-43.55 or earlier is applicable when configured as a Gateway or AAA virtual server.

    • 13.1-61.28 or later requires a SAML action.

    • 13.1-61.27 or earlier is applicable when configured as a Gateway or AAA virtual server.

    • 13.1 FIPS is applicable when configured as a Gateway or AAA virtual server.

CVE-2026-19489 - Memory Overflow

  • Severity: High

  • CVSS: 8.8, CVSS v4.0

  • Description: Improper restriction of memory-buffer operations can cause unpredictable behaviour or denial of service.

  • Impact: Successful exploitation may disrupt appliance availability and may have a limited effect on confidentiality and integrity.

  • Conditions: SIP ALG must be enabled on a Large Scale NAT group configuration.


Mitigation

  • Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the relevant fixed build listed above.

  • For CVE-2026-19489, inspect the NetScaler configuration for add lsn group.*sipalg.* to identify the required precondition.

  • For CVE-2026-19490, inspect the configuration for add authentication samlAction.*, add authentication vserver .* and add vpn vserver .*.

  • Ask any MSP or enterprise IT provider managing the appliances to confirm patching and monitoring for suspicious activity.

  • Notify ASD's ACSC if suspicious activity is detected.

Citrix has published no workaround or mitigating factor. Installing the relevant updated build is required.


Summary for IT Teams

  • Products: Citrix NetScaler ADC and NetScaler Gateway

  • Threat Level: Critical, maximum CVSS 9.3

  • Action Required: Identify customer-managed appliances, verify whether either CVE's configuration preconditions are present, and upgrade all affected systems to the relevant fixed build immediately.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, validate appliance configurations and prioritise remediation. Contact the Secure ISS SOC team on 1300 769 460 or email us for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.