Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix patches critical NetScaler Gateway and AAA authentication bypass CVE-2026-19490 (CVSS 9.3) plus a SIP ALG memory overflow flaw; exploitation attempts observed.
Citrix fixed CVE-2026-19490 (CVSS 9.3), an authentication bypass affecting customer-managed NetScaler ADC and Gateway appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers, and CVE-2026-19489 (CVSS 8.8), a memory overflow causing DoS when SIP ALG is enabled in Large Scale NAT groups. Updates are available in versions 14.1-73.32, 13.1-63.21, and corresponding FIPS/NDcPP builds, while Citrix-managed cloud services were already patched. The flaws were reported by Samarth Vashisht of JPMorgan Chase's penetration-testing team, and Previdian later observed 10 exploitation attempts against CVE-2026-19490 from six unique IP addresses in Australia, Germany, Japan, and the US, with no confirmed compromise.
Citrix security advisory (AV26-833) - Update 1
CISA added actively exploited NetScaler flaw CVE-2026-19490 to its KEV catalog; the Canadian Cyber Centre urges Citrix ADC and Gateway admins to patch.
The Canadian Centre for Cyber Security updated advisory AV26-833 covering Citrix NetScaler ADC and Gateway vulnerabilities in versions 13.1 (prior to 13.1-63.21) and 14.1 (prior to 14.1-73.32), plus FIPS builds. On September 9, 2026, CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog, indicating confirmed exploitation. The bulletin also references CVE-2026-19489 from the Citrix NetScaler ADC and Gateway Security Bulletin. Administrators should apply the fixed builds, including 13.1-37.277 and 14.1-73.32 for FIPS variants.
Citrix security advisory (AV26-645) – Update 3
Canada's Cyber Centre updates Citrix advisory as CVE-2026-8451 and CVE-2026-8452 in NetScaler ADC/Gateway are confirmed exploited in the wild.
The Canadian Centre for Cyber Security updated advisory AV26-645 on August 26, 2026, covering critical vulnerabilities in Citrix NetScaler ADC and Gateway (versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, plus FIPS builds). Open-source reporting indicates CVE-2026-8451 and CVE-2026-8452 are being exploited in the wild. Update 3 references related CISA action, and patched builds were released starting June 30, 2026.