T
Threats
Citrix NetScaler Authentication Bypass and Denial of Service Vulnerabilities
Overview
CVE: CVE-2026-19490, CVE-2026-19489
Severity: Critical
Date: 19 August 2026
Products: NetScaler ADC and NetScaler Gateway
Citrix has published security updates for two remotely exploitable vulnerabilities in customer-managed NetScaler deployments. CVE-2026-19490 is a critical authentication bypass with a CVSS v4.0 score of 9.3. CVE-2026-19489 is a high-severity memory overflow vulnerability with a CVSS v4.0 score of 8.8 that may cause unpredictable behaviour or denial of service.
Affected Versions
NetScaler ADC and NetScaler Gateway 14.1
Affected: Versions before 14.1-73.32
Fixed: 14.1-73.32 and later releases
Not affected: Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group
NetScaler ADC and NetScaler Gateway 13.1
Affected: Versions before 13.1-63.21
Fixed: 13.1-63.21 and later releases of 13.1
Not affected: Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group
NetScaler ADC 14.1 FIPS
Affected: Versions before 14.1-73.32 FIPS
Fixed: 14.1-73.32 FIPS and later releases of 14.1 FIPS
Not affected: No additional unaffected customer-managed configuration is stated by the vendor
NetScaler ADC 13.1 FIPS and NDcPP
Affected: Versions before 13.1-37.277
Fixed: 13.1-37.277 and later releases of 13.1 FIPS and 13.1 NDcPP
Not affected: No additional unaffected customer-managed configuration is stated by the vendor
Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected and must be upgraded to the recommended builds.
Vulnerability Breakdown
CVE-2026-19490 – Authentication Bypass Using an Alternate Path
Severity: Critical
CVSS: 9.3, CVSS v4.0
Description: A remote unauthenticated attacker may bypass authentication through an alternate path on affected NetScaler ADC and NetScaler Gateway deployments.
Impact: Successful exploitation may provide unauthorised access through an affected Gateway or AAA virtual server.
Conditions: The appliance must be configured as a Gateway, including SSL VPN, ICA Proxy, CVPN or RDP Proxy, or as an AAA virtual server. For NetScaler 14.1 build 43.56 or later, 14.1 FIPS build 66.68 or later, and 13.1 build 61.28 or later, the vendor states that a SAML action must also be configured. Earlier affected builds and 13.1 FIPS are exposed under the applicable Gateway or AAA virtual server configuration described in the bulletin.
Configuration checks: Inspect for
add authentication samlAction.*,add authentication vserver .*andadd vpn vserver .*.
CVE-2026-19489 – Memory Overflow and Denial of Service
Severity: High
CVSS: 8.8, CVSS v4.0
Description: A memory overflow vulnerability may cause unpredictable behaviour or denial of service.
Impact: A remote unauthenticated attacker may disrupt the availability of an affected appliance.
Conditions: SIP ALG must be enabled on a Large Scale NAT group configuration.
Configuration check: Inspect for
add lsn group.*sipalg.*.
Mitigation
Identify customer-managed NetScaler ADC and NetScaler Gateway appliances running affected builds.
Check configurations against the vendor-published preconditions for both CVEs.
Upgrade affected appliances to the relevant fixed build immediately.
Include Secure Private Access Hybrid deployments that use customer-managed NetScaler instances in the remediation scope.
Do not rely on a workaround. Citrix states that no workarounds or mitigating factors are available.
Confirm that any marketplace image used for deployment contains the fixed build before use.
Summary for IT Teams
Products: Citrix NetScaler ADC and NetScaler Gateway
Threat Level: Critical, CVSS 9.3
Action Required: Assess exposed Gateway, AAA virtual server and SIP ALG configurations, then upgrade all affected customer-managed appliances to the relevant fixed build immediately.
Reference
Citrix NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490
Citrix Security Update for NetScaler ADC and NetScaler Gateway Vulnerabilities
BleepingComputer – Citrix urges admins to patch new NetScaler flaws as soon as possible
Need Help?
Secure ISS can help your organisation assess affected NetScaler configurations, prioritise internet-facing systems and plan urgent remediation. Call 1300 769 460 or email the Secure ISS team for assistance.

