ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 3 sources: “Exploited Citrix NetScaler auth bypass CVE-2026-19490 lands on CISA KEV with September 12 federal patch deadline” — merged summary and timeline →

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

AI summary · glm-5.3-flash

Canadian Cyber Centre alerts on Citrix NetScaler ADC/Gateway flaws CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (buffer overflow), urging emergency patching.

The Canadian Centre for Cyber Security issued alert AL26-019 covering two Citrix NetScaler vulnerabilities disclosed in a vendor advisory on August 19, 2026. CVE-2026-19490 (CWE-288) allows a remote unauthenticated attacker to bypass authentication on appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. CVE-2026-19489 (CWE-120) is a classic buffer overflow that may cause memory overflow, unpredictable behavior, or denial-of-service conditions. Affected appliances are vulnerable when configured as a SAML IdP; fixed versions include 14.1-73.32, 13.1-63.21, and 13.1-37.277 for FIPS.

  • CVE-2026-19490 enables unauthenticated authentication bypass on SAML IdP-configured NetScaler appliances
  • CVE-2026-19489 is a buffer overflow potentially causing denial of service
  • Fixed in NetScaler 14.1-73.32, 13.1-63.21, and FIPS build 13.1-37.277
  • Cyber Centre recommends emergency patching and monitoring authentication logs for unauthorized access

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19489
Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile).

Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory.

8.8<1%
  • Citrix NetScaler ADC (formerly Citrix ADC) 14.1 releases through build 73.32; 13.1 releases through build 63.21
  • Citrix NetScaler Gateway (formerly Citrix Gateway) 14.1 releases through build 73.32; 13.1 releases through build 63.21
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
Full article595 words · extracted from cyber.gc.ca · click to collapse

Number: AL26-019
Date: September 4, 2026

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway)Footnote 1.  

In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026Footnote 2.

Tracked as CVE-2026-19490Footnote 3, this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288)Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.

Tracked as CVE-2026-19489Footnote 5, this vulnerability is a Classic Buffer Overflow vulnerability (CWE-120)Footnote 6. This vulnerability may allow memory overflow leading to unpredictable behavior or Denial of Service conditions.

Pre-conditions for these vulnerabilities are that the NetScaler ADC or NetScaler Gateway 14.1-43.56 and later, as well as 13.1-61.28 and later, must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider).

Earlier builds with Gateway or AAA configuration are also vulnerable.

To determine if organizations are impacted, it is recommended to check if the appliance meets the precondition by inspecting the NetScaler configuration for the specified strings:

For CVE-2026-19489:

"add lsn group.*sipalg.*"

For CVE-2026-19490:

SAML action configuration:

"add authentication samlAction.*"

Auth or VPN vserver:

"add authentication vserver .*" or "add vpn vserver .*"

Further information about the impacted configurations can be found in the Citrix advisoryFootnote 1.

Suggested actions

The Cyber Centre recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances (particularly for SAML IDP-configured appliances), review the Citrix security bulletinFootnote 1 and update/upgrade the affected systems to the following vendor-supported fixed versions:

Affected product Affected versions Fixed versions
NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.32 version 14.1-73.32 and later
NetScaler ADC and NetScaler Gateway 13.1 versions prior to 13.1-63.21 version 13.1-63.21 and later
NetScaler ADC FIPS versions prior to 14.1-73.32 FIPS version 14.1-73.32 FIPS and later
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277 version 13.1-37.277 and later

The Cyber Centre also recommends organizations to:

  • determine the current version of software on each appliance
  • identify NetScaler appliances configured as Gateway services or AAA virtual servers
  • review configurations for SAML authentication deployments, where applicable
  • prioritize patching affected systems on an emergency basis
  • monitor authentication logs and network activity for indications of unauthorized access
  • follow Citrix incident response guidance if compromise is suspected
  • after patching, verify the appliance is running the updated version and review logs for unusual activity

Citrix has provided steps to take if NetScaler ADC or NetScaler Gateway are suspected to be compromisedFootnote 7.

In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security ActionsFootnote 8 with an emphasis on the following topics:

  • consolidate, monitor, and defend Internet gateways
  • patch operating systems and applications
  • harden operating systems and applications
  • isolate web-facing applications

Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal, or email [email protected].

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489