Threat Advisories

Citrix NetScaler Authentication Bypass and DoS vulnerabilities require immediate patching

Written by Integrity360 | Aug 20, 2026, 2:08:04 PM

Citrix has issued an urgent advisory warning customers to patch two newly disclosed vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. The most severe vulnerability, CVE-2026-19490, enables unauthenticated authentication bypass under specific configurations, potentially allowing remote attackers to gain unauthorized access to exposed services. A second vulnerability, CVE-2026-19489, could enable unauthenticated attackers to trigger denial-of-service (DoS) conditions.

Although Citrix has not reported active exploitation at the time of publication, the vendor is strongly recommending immediate remediation. This warning is particularly significant given the history of NetScaler vulnerabilities being weaponised shortly after disclosure.

CVE-2026-19489

Severity: High

Description: A memory overflow vulnerability affecting appliances where SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled within large-scale NAT group configurations. The flaw can be abused remotely without authentication to trigger denial-of-service conditions.

Potential Impact:

  • Service disruption
  • VPN and remote access outages
  • Business continuity impacts
  • Potential interruption of voice or communication services

Vulnerability Details

Severity: Critical

Description: An authentication bypass vulnerability affecting NetScaler deployments configured as:

  • AAA Virtual Servers
  • NetScaler Gateway
  • SSL VPN
  • ICA Proxy
  • CVPN
  • RDP Proxy

The vulnerability may allow a remote, unauthenticated attacker to bypass authentication controls depending on firmware version and SAML configuration.

Potential Impact:

  • Unauthorized access to corporate remote access infrastructure
  • Exposure of internal applications and resources
  • Potential privilege escalation following initial access
  • Increased risk of credential theft and lateral movement

Affected Products

Citrix states the vulnerabilities affect supported versions of:

  • NetScaler ADC
  • NetScaler Gateway
  • NetScaler ADC FIPS
  • NetScaler ADC NDcPP
  • Secure Access ZTNA Hybrid deployments using customer-managed NetScaler instances

Recommended Remediation

Citrix recommends upgrading affected appliances to the following builds or later:

  • NetScaler ADC / Gateway 14.1-73.32
  • NetScaler ADC / Gateway 13.1-63.21
  • NetScaler ADC FIPS 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP 13.1-37.277

Validation Checks

Administrators should review NetScaler configurations to determine exposure:

For CVE-2026-19490

  • Check for SAML Action configuration:
    • add authentication samlAction
  • Check for authentication or VPN virtual servers:
    • add authentication vserver
    • add vpn vserver

For CVE-2026-19489

  • Check for SIP ALG-enabled large-scale NAT groups:
    • add lsn group ... sipalg ...

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.