Citrix NetScaler ADC and Gateway Vulnerabilities CVE-2026-19490 and CVE-2026-19489 Require Urgent Patching

Published:

Advisory Number: AL26-019
Date: September 4, 2026

Urgent Security Advisory for Citrix NetScaler ADC and Gateway

The Canadian Centre for Cyber Security has issued an urgent advisory regarding critical vulnerabilities affecting Citrix NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). These vulnerabilities, tracked as CVE-2026-19490 and CVE-2026-19489, require immediate attention from IT professionals and organizations utilizing these systems.

CVE-2026-19490 is classified as an Authentication Bypass Using an Alternate Path vulnerability (CWE-288). This flaw could allow a remote, unauthenticated attacker to bypass authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Meanwhile, CVE-2026-19489 is identified as a Classic Buffer Overflow vulnerability (CWE-120), which may lead to memory overflow, resulting in unpredictable behavior or Denial of Service conditions.

Vulnerable Versions and Impact

These vulnerabilities affect NetScaler ADC and NetScaler Gateway versions 14.1-43.56 and later, as well as 13.1-61.28 and later, specifically when configured as a SAML Identity Provider (IdP). Earlier builds with Gateway or AAA configurations are also at risk.

To assess whether your organization is impacted, check the NetScaler configuration for the following strings:

For CVE-2026-19489:

add lsn group.*sipalg.*

For CVE-2026-19490:

SAML action configuration:

add authentication samlAction.*

Auth or VPN vserver:

add authentication vserver .* or add vpn vserver .*

For further details on the affected configurations, refer to the Citrix security bulletin.

Recommended Actions

The Cyber Centre strongly advises organizations to review the Citrix security bulletin and promptly update or upgrade affected systems to the following fixed versions:

Affected Product Affected Versions Fixed Versions
NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.32 version 14.1-73.32 and later
NetScaler ADC and NetScaler Gateway 13.1 versions prior to 13.1-63.21 version 13.1-63.21 and later
NetScaler ADC FIPS versions prior to 14.1-73.32 FIPS version 14.1-73.32 FIPS and later
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277 version 13.1-37.277 and later

In addition to patching, organizations should:

  • Determine the current software version on each appliance.
  • Identify NetScaler appliances configured as Gateway services or AAA virtual servers.
  • Review configurations for SAML authentication deployments, where applicable.
  • Prioritize patching affected systems on an emergency basis.
  • Monitor authentication logs and network activity for signs of unauthorized access.
  • Follow Citrix incident response guidance if a compromise is suspected.
  • After patching, verify that the appliance is running the updated version and review logs for unusual activity.

For organizations that suspect their NetScaler ADC or NetScaler Gateway may have been compromised, Citrix has provided specific steps to follow.

Furthermore, the Cyber Centre recommends reviewing and implementing its Top 10 IT Security Actions, focusing on consolidating and defending Internet gateways, patching operating systems and applications, hardening systems, and isolating web-facing applications.

For more information, please refer to the full advisory from the Canadian Centre for Cyber Security here.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

HPE security advisory AV26-1011 warns of vulnerabilities in AOS-S and CPPM products

Hewlett Packard Enterprise (HPE) has issued a security advisory (AV26-1011) regarding vulnerabilities affecting its AOS-Switch and ClearPass Policy Manager (CPPM) products. As of October...

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...