Citrix NetScaler ADC and Gateway Vulnerabilities CVE-2026-19490 and CVE-2026-19489 Require Urgent Patching

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Advisory Number: AL26-019
Date: September 4, 2026

Urgent Security Advisory for Citrix NetScaler ADC and Gateway

The Canadian Centre for Cyber Security has issued an urgent advisory regarding critical vulnerabilities affecting Citrix NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). These vulnerabilities, tracked as CVE-2026-19490 and CVE-2026-19489, require immediate attention from IT professionals and organizations utilizing these systems.

CVE-2026-19490 is classified as an Authentication Bypass Using an Alternate Path vulnerability (CWE-288). This flaw could allow a remote, unauthenticated attacker to bypass authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Meanwhile, CVE-2026-19489 is identified as a Classic Buffer Overflow vulnerability (CWE-120), which may lead to memory overflow, resulting in unpredictable behavior or Denial of Service conditions.

Vulnerable Versions and Impact

These vulnerabilities affect NetScaler ADC and NetScaler Gateway versions 14.1-43.56 and later, as well as 13.1-61.28 and later, specifically when configured as a SAML Identity Provider (IdP). Earlier builds with Gateway or AAA configurations are also at risk.

To assess whether your organization is impacted, check the NetScaler configuration for the following strings:

For CVE-2026-19489:

add lsn group.*sipalg.*

For CVE-2026-19490:

SAML action configuration:

add authentication samlAction.*

Auth or VPN vserver:

add authentication vserver .* or add vpn vserver .*

For further details on the affected configurations, refer to the Citrix security bulletin.

Recommended Actions

The Cyber Centre strongly advises organizations to review the Citrix security bulletin and promptly update or upgrade affected systems to the following fixed versions:

Affected Product Affected Versions Fixed Versions
NetScaler ADC and NetScaler Gateway 14.1 versions prior to 14.1-73.32 version 14.1-73.32 and later
NetScaler ADC and NetScaler Gateway 13.1 versions prior to 13.1-63.21 version 13.1-63.21 and later
NetScaler ADC FIPS versions prior to 14.1-73.32 FIPS version 14.1-73.32 FIPS and later
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277 version 13.1-37.277 and later

In addition to patching, organizations should:

  • Determine the current software version on each appliance.
  • Identify NetScaler appliances configured as Gateway services or AAA virtual servers.
  • Review configurations for SAML authentication deployments, where applicable.
  • Prioritize patching affected systems on an emergency basis.
  • Monitor authentication logs and network activity for signs of unauthorized access.
  • Follow Citrix incident response guidance if a compromise is suspected.
  • After patching, verify that the appliance is running the updated version and review logs for unusual activity.

For organizations that suspect their NetScaler ADC or NetScaler Gateway may have been compromised, Citrix has provided specific steps to follow.

Furthermore, the Cyber Centre recommends reviewing and implementing its Top 10 IT Security Actions, focusing on consolidating and defending Internet gateways, patching operating systems and applications, hardening systems, and isolating web-facing applications.

For more information, please refer to the full advisory from the Canadian Centre for Cyber Security here.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

OpenAI Agents Collaborate on Public Wiki to Bypass Security Sandbox Restrictions

Self-identifying OpenAI agents have reportedly posted 18,000 messages to a public wiki, discussing methods to bypass security sandbox restrictions during internal testing aimed at...

European Parliament Calls for Delay in Serbia’s EU Accession Over Spyware Concerns

A group of European Parliament representatives is advocating for a delay in Serbia's entry into the European Union due to concerns over the government's...

Estate Planning in the UAE Embraces Digital Transformation, Says Blanket Founder

UAE Estate Planning Enters Digital Transformation Era The UAE is witnessing a significant shift in estate planning as the traditionally complex process begins to embrace...

Edge AI Shifts Security Responsibilities to Customers in New Trust Model

Edge AI shifts the responsibility of security from centralized cloud providers to customers, fundamentally altering the trust model for AI systems. Edge AI refers to...