T
Threats
Citrix NetScaler ADC and Gateway Critical Vulnerabilities
Overview
CVE: CVE-2026-19490, CVE-2026-19489
Severity: Critical
Date: 8 September 2026
Vendor publication: 19 August 2026
ACSC alert: 4 September 2026
Citrix has released security updates for two vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-19490 is a critical authentication-bypass vulnerability with a CVSS v4.0 score of 9.3. CVE-2026-19489 is a high-severity memory-overflow vulnerability with a CVSS v4.0 score of 8.8.
Both flaws affect customer-managed appliances only when their stated configuration preconditions are present. As these products commonly operate at the network edge, Australian organisations should assess exposure and install the relevant fixed build as soon as practicable.
Affected Versions
The following supported releases are affected when the relevant CVE preconditions described below are met.
NetScaler ADC and NetScaler Gateway 14.1
Affected: Versions before 14.1-73.32
Fixed: 14.1-73.32 and later releases
NetScaler ADC and NetScaler Gateway 13.1
Affected: Versions before 13.1-63.21
Fixed: 13.1-63.21 and later releases of 13.1
NetScaler ADC FIPS 14.1
Affected: Versions before 14.1-73.32 FIPS
Fixed: 14.1-73.32 FIPS and later releases of 14.1-FIPS
NetScaler ADC FIPS and NDcPP 13.1
Affected: Versions before 13.1-37.277
Fixed: 13.1-37.277 and later releases of 13.1-FIPS and 13.1-NDcPP
Secure Private Access Hybrid deployments that use NetScaler instances are also affected and must upgrade those instances to the recommended builds. The bulletin applies to customer-managed NetScaler ADC and NetScaler Gateway. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have received the necessary software updates from Cloud Software Group.
Vulnerability Breakdown
CVE-2026-19490 - Authentication Bypass Using an Alternate Path
Severity: Critical
CVSS: 9.3, CVSS v4.0
Description: An alternate authentication path can bypass expected authentication controls when an affected appliance meets specified Gateway, AAA virtual server or SAML configuration requirements.
Impact: Successful exploitation may allow unauthorised access and compromise the confidentiality, integrity and availability of affected systems.
Conditions:
14.1-43.56 or later requires a SAML action and a Gateway or AAA virtual server configuration.
14.1-66.68-FIPS or later requires a SAML action and a Gateway or AAA virtual server configuration.
14.1-43.55 or earlier is applicable when configured as a Gateway or AAA virtual server.
13.1-61.28 or later requires a SAML action.
13.1-61.27 or earlier is applicable when configured as a Gateway or AAA virtual server.
13.1 FIPS is applicable when configured as a Gateway or AAA virtual server.
CVE-2026-19489 - Memory Overflow
Severity: High
CVSS: 8.8, CVSS v4.0
Description: Improper restriction of memory-buffer operations can cause unpredictable behaviour or denial of service.
Impact: Successful exploitation may disrupt appliance availability and may have a limited effect on confidentiality and integrity.
Conditions: SIP ALG must be enabled on a Large Scale NAT group configuration.
Mitigation
Upgrade affected NetScaler ADC and NetScaler Gateway appliances to the relevant fixed build listed above.
For CVE-2026-19489, inspect the NetScaler configuration for
add lsn group.*sipalg.*to identify the required precondition.For CVE-2026-19490, inspect the configuration for
add authentication samlAction.*,add authentication vserver .*andadd vpn vserver .*.Ask any MSP or enterprise IT provider managing the appliances to confirm patching and monitoring for suspicious activity.
Notify ASD's ACSC if suspicious activity is detected.
Citrix has published no workaround or mitigating factor. Installing the relevant updated build is required.
Summary for IT Teams
Products: Citrix NetScaler ADC and NetScaler Gateway
Threat Level: Critical, maximum CVSS 9.3
Action Required: Identify customer-managed appliances, verify whether either CVE's configuration preconditions are present, and upgrade all affected systems to the relevant fixed build immediately.
Reference
Citrix NetScaler Security Bulletin for CVE-2026-19489 and CVE-2026-19490
ASD's ACSC Alert: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
Need Help?
Secure ISS can help your organisation assess exposure, validate appliance configurations and prioritise remediation. Contact the Secure ISS SOC team on 1300 769 460 or email us for assistance.

