Citrix heeft twee kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. CVE-2026-19489 betreft een memory overflow die optreedt wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep, wat kan leiden tot denial of service of onvoorspelbaar gedrag. CVE-2026-19490 stelt aanvallers in staat authenticatiemechanismen te omzeilen voor ongeautoriseerde toegang, waarbij de producten geconfigureerd moeten zijn als Gateway, AAA virtual server of SAML Identity Provider. Er is Proof of Concept code beschikbaar voor CVE-2026-19490. Het NCSC acht het zeer waarschijnlijk dat op korte termijn actief misbruik zal plaatsvinden van CVE-2026-19490. Organisaties worden geadviseerd de beschikbare patches zo snel mogelijk toe te passen.
Two vulnerabilities were patched in Citrix NetScaler ADC and NetScaler Gateway. CVE-2026-19489 is a memory overflow vulnerability triggered when the products are configured as SIP ALG within a Large Scale NAT (LSN) group. This memory allocation error can cause unpredictable behavior or a denial of service. CVE-2026-19490 allows an attacker to bypass normal authentication mechanisms via an alternative route to gain unauthorized access. Exploitation requires the products to be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual server, or as a SAML Identity Provider. Proof of Concept code is available for CVE-2026-19490, and the NCSC considers it highly likely that exploitation will occur in the short term.
Apply the updates released by Citrix for NetScaler ADC and NetScaler Gateway immediately. Prioritize patching CVE-2026-19490 as Proof of Concept code is publicly available and exploitation is considered highly likely in the short term. Review configurations to determine if products are set up as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy), AAA virtual server, or SAML Identity Provider, as these are at risk for CVE-2026-19490. For CVE-2026-19489, check if SIP ALG is configured within a Large Scale NAT (LSN) group. Refer to the Citrix support article CTX696939 for detailed remediation guidance.