Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix patches critical NetScaler Gateway and AAA authentication bypass CVE-2026-19490 (CVSS 9.3) plus a SIP ALG memory overflow flaw; exploitation attempts observed.
Citrix fixed CVE-2026-19490 (CVSS 9.3), an authentication bypass affecting customer-managed NetScaler ADC and Gateway appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers, and CVE-2026-19489 (CVSS 8.8), a memory overflow causing DoS when SIP ALG is enabled in Large Scale NAT groups. Updates are available in versions 14.1-73.32, 13.1-63.21, and corresponding FIPS/NDcPP builds, while Citrix-managed cloud services were already patched. The flaws were reported by Samarth Vashisht of JPMorgan Chase's penetration-testing team, and Previdian later observed 10 exploitation attempts against CVE-2026-19490 from six unique IP addresses in Australia, Germany, Japan, and the US, with no confirmed compromise.
- CVE-2026-19490 bypass applies to Gateway or AAA vserver configurations; SAML action matters on newer builds.
- CVE-2026-19489 only triggers with SIP ALG enabled in LSN group configurations.
- NetScaler Console Global Deny Lists signatures can mitigate the authentication bypass.
- Previdian recorded 10 exploitation attempts from six IPs; no confirmed compromise.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19489 | Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile). Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory. | 8.8 | <1% |
| mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds) | ||
| CVE-2026-19490 | Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile). Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected. | 9.3 | 6% | KEV PoC |
| largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances | |
| CVE-2026-8451 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML ID Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP NVD description · AI analysis pending | 8.8 | 16% |
| — |
Full article723 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 20, 2026Network Security / Enterprise Security
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.
It bears noting that the vulnerabilities do not apply to Citrix-managed cloud services or Citrix-managed Adaptive Authentication, as the necessary updates have already been applied. The list of impacted NetScaler versions is below -
- NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
- NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
- NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
The first of the two vulnerabilities is CVE-2026-19489 (CVSS score: 8.8), a memory overflow vulnerability that may lead to unpredictable behavior or denial-of-service (DoS). However, it applies only when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT (LSN) group configuration.
CVE-2026-19490 (CVSS score: 9.3), the more severe of the two, is an authentication bypass vulnerability that affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, assuming the following version-specific requirements are met -
- 14.1-43.56 or later - Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
- 14.1-66.68-FIPS or later - Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
- 14.1-43.55 or earlier - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver
- 13.1-61.28 or later - Applicable only when configured with a SAML action
- 13.1-61.27 or earlier - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
- 13.1 FIPS - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
"Customers should also review their configurations to determine whether the documented preconditions apply," Citrix said. "Prioritization should be based on exposure, deployment role, and whether the affected configuration is enabled."
For CVE-2026-19489, customers can check if their device meets the precondition by inspecting their NetScaler configuration for the specified string -
- add lsn group.*sipalg.*
Similarly, for CVE-2026-19490, customers can verify their NetScaler configuration for the below string -
- add authentication samlAction.* (SAML action configuration)
- add authentication vserver .* or add vpn vserver .* (for AAA or VPN vserver)
"Additionally, this vulnerability can be mitigated by using signatures if you are using NetScaler Console (Service or on-prem) and if the NetScaler firmware version is higher than 14.1-60.52 and 13.1-63.16 or higher, which have a feature called Global Deny Lists that consumes the signatures and automatically applies the signatures to NetScaler appliances managed via NetScaler Console," Citrix said. "The feature is enabled by default."
The updates are available in the following versions -
- NetScaler ADC and NetScaler Gateway 14.1-73.32 or later
- NetScaler ADC and NetScaler Gateway 13.1-63.21 or later
- NetScaler ADC FIPS 14.1-73.32 FIPS or later
- NetScaler ADC FIPS and NDcPP 13.1-37.277 or later
Citrix has credited Samarth Vashisht from the pen-test team at JPMorgan Chase for discovering and reporting the flaws. Although there is no evidence that the shortcomings have been exploited in the wild, newly disclosed Citrix vulnerabilities have been a lucrative target for attackers.
Last month, an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway (CVE-2026-8451, CVSS score: 8.8) witnessed active exploitation efforts less than 24 hours of public disclosure.
Update
As of September 3, Previdian said it has observed exploitation attempts against CVE-2026-19490 targeting its NetScaler sensors. Telemetry gathered by the threat intelligence firm shows 10 exploitation attempts coming from six unique IP addresses in Australia, Germany, Japan, and the U.S.
"Our current assessment is that this provides evidence of exploitation attempts, but it does not confirm successful compromise of real-world systems," Previdian founder Ryan Dewhurst told The Hacker News via email.
(The story was updated after publication on September 4, 2026, to include details of active exploitation of CVE-2026-19490.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html