ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

AI summary · glm-5.3-flash

Citrix patched a critical authentication bypass, CVE-2026-19490, in NetScaler Gateway and NetScaler ADC, urging customers to upgrade immediately.

Citrix has patched two flaws in NetScaler ADC and NetScaler Gateway. CVE-2026-19490 is a critical authentication bypass (CVSS v4.0 9.3) that works when the appliance is configured as an SSL VPN, ICA Proxy, CVPN, RDP Proxy Gateway or AAA virtual server, with additional conditions depending on firmware and SAML configuration. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow that can cause denial of service when SIP ALG is enabled on LSN setups. Rapid7 had not observed exploitation as of August 19, 2026, but urged emergency patching; a signature-based mitigation is available via NetScaler Console.

  • CVE-2026-19490 is a critical authentication bypass with CVSS v4.0 score 9.3
  • Affects NetScaler ADC and Gateway 14.1 and 13.1 builds, including FIPS and NDcPP
  • CVE-2026-19489 is a memory overflow (CVSS 8.8) causing DoS when SIP ALG is enabled
  • No exploitation observed as of August 19, 2026 per Rapid7
  • Signature mitigation available via NetScaler Console Global Deny Lists

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-19489
Unauthenticated Buffer Overflow in Citrix NetScaler ADC and NetScaler Gateway

CVE-2026-19489 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway classified as a classic buffer overflow (CWE-120), meaning input is copied into a buffer without adequate size checks; it was disclosed by Citrix alongside CVE-2026-19490, the authentication bypass receiving most of the headline attention. Per the CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated remote attacker with no user interaction, though detailed trigger conditions are not spelled out in the CVE description. The scoring (VC:L/VI:L/VA:H, base 8.8 High) indicates the primary impact is to availability — likely crashes or denial of service on the appliance — with low confidentiality and integrity impact. All organizations running NetScaler ADC or NetScaler Gateway 14.1 releases through build 73.32, or 13.1 releases through build 63.21, fall within the affected ranges. There is no evidence of exploitation so far: the issue is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days (32nd percentile).

Do: Upgrade affected NetScaler ADC and NetScaler Gateway deployments to the fixed builds identified in Citrix's advisory (see AL26-019 and CISA advisory AV26-833 Update 1); affected ranges are 14.1 through build 73.32 and 13.1 through build 63.21. Until patched, limit internet exposure of appliance interfaces and monitor Citrix channels for signs of exploitation. Also verify whether the same appliances are affected by the related CVE-2026-19490 authentication bypass fixed in the same advisory.

8.8<1%
  • Citrix NetScaler ADC (formerly Citrix ADC) 14.1 releases through build 73.32; 13.1 releases through build 63.21
  • Citrix NetScaler Gateway (formerly Citrix Gateway) 14.1 releases through build 73.32; 13.1 releases through build 63.21
mass≈100,000+ internet-exposed NetScaler ADC/Gateway appliances (order-of-magnitude estimate; not all run affected builds)
CVE-2026-19490
Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile).

Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected.

9.36% KEV PoC
  • Citrix NetScaler ADC and NetScaler Gateway
largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances
Full article550 words · extracted from helpnetsecurity.com · click to collapse

Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible.

OPIS

“We strongly recommend that customers review the official NetScaler ADC and NetScaler Gateway security bulletin, assess whether their deployments are affected, and upgrade impacted appliances to the recommended builds as soon as possible,” Anil Shetty, senior VP of Engineering with Cloud Software Group (Citrix’s parent company), warned on Wednesday.

“The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds. SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds,” added Shetty.

Rapid7 said it had not observed exploitation of CVE-2026-19490 as of August 19, 2026, but urged organizations to “prioritize patching affected systems on an emergency basis,” since Citrix products tend to draw quick exploitation once flaws become public.

The vulnerabilities (CVE-2026-19489, CVE-2026-19490)

CVE-2026-19490 is the more concerning of the two, with a CVSS v4.0 score of 9.3. It allows an attacker to bypass login checks using an alternate path, but only under specific conditions. The appliance has to be configured as a Gateway, covering SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.

Whether it is exposed also depends on the firmware version and whether a SAML action is configured. On older firmware, the Gateway or AAA configuration alone is enough to meet the precondition, without SAML being configured. The exact version thresholds differ between standard and FIPS builds.

Security teams can check whether they meet the precondition by searching their NetScaler configuration for “add authentication samlAction” to spot a SAML action setup, or for “add authentication vserver” and “add vpn vserver” to spot an Auth or VPN virtual server.

“Additionally, this vulnerability can be mitigated by using signatures if you are using NetScaler Console (Service or on-prem) and if the NetScaler firmware version is higher than 14.1-60.52 and 13.1-63.16 or higher which have a feature called Global Deny Lists which consumes the signatures and automatically applies the signatures to NetScaler appliances managed via NetScaler Console,” noted Shetty.

The second flaw, CVE-2026-19489, is a memory overflow issue with a CVSS v4.0 score of 8.8 that can cause unpredictable behavior or denial of service. It only applies when SIP ALG is enabled on a Large Scale NAT group setup, another narrow precondition.

Security teams can check exposure to the second flaw by searching their configuration for “add lsn group” combined with “sipalg”.

The vulnerabilities affect:

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
  • NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277

“Once you upgrade a NetScaler in an ICA proxy setup to version 14.1-72.16 (or 13.1-63.18) or later, any ICA session that attempts to reconnect using a session ticket issued by the older (pre-upgrade) version is dropped. As a result, users must launch the session again. This is a security measure and not an after effect of upgrade activity,” Shetty explained.

At the time of Citrix’s advisory, the NetScaler images listed on AWS, Azure, and GCP marketplaces had not been refreshed with the patched builds.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/