NewsSecurity Vulnerabilities

Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490)

Security teams are being urged to update Citrix NetScaler appliances after two vulnerabilities were disclosed that could allow attackers to bypass authentication or cause systems to crash.

The vulnerabilities, tracked as CVE-2026-19489 and CVE-2026-19490, affect NetScaler ADC and NetScaler Gateway, products widely used to provide application delivery, remote access and VPN services.

CVE-2026-19489 is a memory overflow vulnerability with a CVSS 4.0 score of 8.8. The flaw can result in unpredictable behaviour and denial-of-service conditions. It requires SIP ALG to be enabled on a Large Scale NAT (LSN) group configuration.

The more serious of the two vulnerabilities is CVE-2026-19490, which has a CVSS 4.0 score of 9.3 (Critical). The vulnerability is an authentication bypass using an alternate path, potentially allowing a remote, unauthenticated attacker to bypass authentication and gain access to protected services.

The vulnerability is particularly concerning because NetScaler Gateway can provide access to corporate resources through technologies including SSL VPN, ICA Proxy, CVPN and RDP Proxy.

Affected NetScaler versions

The vulnerabilities affect supported versions of NetScaler ADC and NetScaler Gateway, including:

  • NetScaler ADC/Gateway 14.1 before 14.1-73.32
  • NetScaler ADC/Gateway 13.1 before 13.1-63.21
  • NetScaler ADC FIPS versions before 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP versions before 13.1-37.277

CVE-2026-19490 has additional configuration requirements depending on the NetScaler version, including Gateway or AAA virtual-server configurations and, on newer releases, SAML configurations.

Administrators urged to patch

Citrix disclosed the vulnerabilities on 19 August 2026, with European and UK cybersecurity organisations subsequently warning administrators to apply the available security updates.

NHS England’s cybersecurity service specifically warned that CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication.

NetScaler provides remediation guidance through its security advisory tools, with administrators advised to upgrade affected appliances to a release containing the fixes.

Organisations using NetScaler ADC or NetScaler Gateway should therefore check their appliance versions and configurations and prioritise the installation of the relevant security updates, particularly where NetScaler is exposed to the internet.

With NetScaler often sitting at the edge of corporate networks and providing remote access to internal applications, an authentication bypass vulnerability could present a significant security risk if left unpatched.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.