Citrix has released security updates addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway. The most severe is a critical authentication bypass flaw affecting customer-managed deployments. The vulnerability impacts certain FIPS and NDcPP builds as well as SecurAccess configurations. Both NetScaler ADC and NetScaler Gateway products are affected. The flaws are specific to customer-managed environments rather than Citrix-managed cloud services. Organizations running affected versions are urged to apply the patches immediately given the critical severity rating. Authentication bypass vulnerabilities in gateway and AAA servers pose significant risk as they can allow unauthorized access to protected resources.
Citrix released patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway. CVE-2026-19489 (CVSS 8.8) is a memory overflow vulnerability that can cause unpredictable behavior or denial-of-service (DoS), triggered only when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT (LSN) group configuration. CVE-2026-19490 (CVSS 9.3) is a critical authentication bypass vulnerability affecting appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The authentication bypass has version-specific conditions: for versions 14.1-43.56 or later and 13.1-61.28 or later, it requires a SAML action configuration; for versions 14.1-43.55 or earlier, 13.1-61.27 or earlier, and 13.1 FIPS, it applies broadly to Gateway or AAA vserver configurations. The vulnerabilities affect customer-managed instances only; Citrix-managed cloud services are not affected. Discovered by Samarth Vashisht from the pen-test team at JPMorgan Chase. No evidence of in-the-wild exploitation at time of disclosure.
1. Upgrade to patched versions immediately: NetScaler ADC and NetScaler Gateway 14.1-73.32 or later, NetScaler ADC and NetScaler Gateway 13.1-63.21 or later, NetScaler ADC FIPS 14.1-73.32 FIPS or later, NetScaler ADC FIPS and NDcPP 13.1-37.277 or later. 2. Review configurations to determine if preconditions apply: For CVE-2026-19489, inspect configuration for 'add lsn group.*sipalg.*'; For CVE-2026-19490, inspect for 'add authentication samlAction.*' and 'add authentication vserver .* or add vpn vserver .*'. 3. Prioritize patching based on exposure, deployment role, and whether affected configurations are enabled. 4. For CVE-2026-19490, apply mitigation via NetScaler Console (Service or on-prem) using signatures and the Global Deny Lists feature if NetScaler firmware is higher than 14.1-60.52 or 13.1-63.16 — this feature is enabled by default. 5. Note that Citrix-managed cloud services and Citrix-managed Adaptive Authentication are already patched and require no action.