T

Threats

Citrix NetScaler Authentication Bypass and Denial of Service Vulnerabilities

Overview

Citrix has published security updates for two remotely exploitable vulnerabilities in customer-managed NetScaler deployments. CVE-2026-19490 is a critical authentication bypass with a CVSS v4.0 score of 9.3. CVE-2026-19489 is a high-severity memory overflow vulnerability with a CVSS v4.0 score of 8.8 that may cause unpredictable behaviour or denial of service.


Affected Versions

NetScaler ADC and NetScaler Gateway 14.1

  • Affected: Versions before 14.1-73.32

  • Fixed: 14.1-73.32 and later releases

  • Not affected: Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group

  • Source: Citrix NetScaler security bulletin CTX696939

NetScaler ADC and NetScaler Gateway 13.1

  • Affected: Versions before 13.1-63.21

  • Fixed: 13.1-63.21 and later releases of 13.1

  • Not affected: Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group

  • Source: Citrix NetScaler security bulletin CTX696939

NetScaler ADC 14.1 FIPS

  • Affected: Versions before 14.1-73.32 FIPS

  • Fixed: 14.1-73.32 FIPS and later releases of 14.1 FIPS

  • Not affected: No additional unaffected customer-managed configuration is stated by the vendor

  • Source: Citrix NetScaler security bulletin CTX696939

NetScaler ADC 13.1 FIPS and NDcPP

  • Affected: Versions before 13.1-37.277

  • Fixed: 13.1-37.277 and later releases of 13.1 FIPS and 13.1 NDcPP

  • Not affected: No additional unaffected customer-managed configuration is stated by the vendor

  • Source: Citrix NetScaler security bulletin CTX696939

Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also affected and must be upgraded to the recommended builds.


Vulnerability Breakdown

CVE-2026-19490 – Authentication Bypass Using an Alternate Path

  • Severity: Critical

  • CVSS: 9.3, CVSS v4.0

  • Description: A remote unauthenticated attacker may bypass authentication through an alternate path on affected NetScaler ADC and NetScaler Gateway deployments.

  • Impact: Successful exploitation may provide unauthorised access through an affected Gateway or AAA virtual server.

  • Conditions: The appliance must be configured as a Gateway, including SSL VPN, ICA Proxy, CVPN or RDP Proxy, or as an AAA virtual server. For NetScaler 14.1 build 43.56 or later, 14.1 FIPS build 66.68 or later, and 13.1 build 61.28 or later, the vendor states that a SAML action must also be configured. Earlier affected builds and 13.1 FIPS are exposed under the applicable Gateway or AAA virtual server configuration described in the bulletin.

  • Configuration checks: Inspect for add authentication samlAction.*, add authentication vserver .* and add vpn vserver .*.

  • Source: Citrix NetScaler security bulletin CTX696939

CVE-2026-19489 – Memory Overflow and Denial of Service

  • Severity: High

  • CVSS: 8.8, CVSS v4.0

  • Description: A memory overflow vulnerability may cause unpredictable behaviour or denial of service.

  • Impact: A remote unauthenticated attacker may disrupt the availability of an affected appliance.

  • Conditions: SIP ALG must be enabled on a Large Scale NAT group configuration.

  • Configuration check: Inspect for add lsn group.*sipalg.*.

  • Source: Citrix NetScaler security bulletin CTX696939


Mitigation

  • Identify customer-managed NetScaler ADC and NetScaler Gateway appliances running affected builds.

  • Check configurations against the vendor-published preconditions for both CVEs.

  • Upgrade affected appliances to the relevant fixed build immediately.

  • Include Secure Private Access Hybrid deployments that use customer-managed NetScaler instances in the remediation scope.

  • Do not rely on a workaround. Citrix states that no workarounds or mitigating factors are available.

  • Confirm that any marketplace image used for deployment contains the fixed build before use.


Summary for IT Teams

  • Products: Citrix NetScaler ADC and NetScaler Gateway

  • Threat Level: Critical, CVSS 9.3

  • Action Required: Assess exposed Gateway, AAA virtual server and SIP ALG configurations, then upgrade all affected customer-managed appliances to the relevant fixed build immediately.


Reference


Need Help?

Secure ISS can help your organisation assess affected NetScaler configurations, prioritise internet-facing systems and plan urgent remediation. Call 1300 769 460 or email the Secure ISS team for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.