Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on the NetScaler firmware version and whether SAML Action is configured. Admins can check if an appliance is vulnerable to attacks targeting CVE-2026-19490 by inspecting their NetScaler configuration for SAML action configuration (add authentication samlAction .*) string and Auth or VPN vserver ('add authentication vserver .*' and 'add vpn vserver .*') strings. The second, a high-severity memory overflow security flaw tracked as CVE-2026-19489, can be abused by remote unauthenticated threat actors in denial-of-service (DoS) attacks when SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a large-scale NAT group configuration. Security teams can determine whether Citrix NetScaler appliances on their network meet the preconditions for CVE-2026-19489 exploitation by inspecting their configuration for the "add lsn group.*sipalg.*" string. Citrix advised customers to upgrade vulnerable NetScaler ADC and NetScaler Gateway appliances to: "We strongly recommend that customers review the official NetScaler ADC and NetScaler G...
Citrix urges admins to patch new NetScaler flaws as soon as possible
Affected Software
Frequently Asked Questions
Which NetScaler deployments are affected by CVE-2026-19490?
The authentication-bypass flaw can affect NetScaler Gateway secure remote access solutions and NetScaler ADC appliances configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy. Exposure depends on the NetScaler firmware version and whether SAML Action is configured.
How can administrators check for configuration exposure to CVE-2026-19490?
Administrators can inspect the NetScaler configuration for SAML action entries matching "add authentication samlAction .*" and for authentication or VPN virtual-server entries matching "add authentication vserver .*" and "add vpn vserver .*".
What could an attacker do with CVE-2026-19490?
A remote attacker without privileges may be able to bypass authentication on affected configurations.
When is CVE-2026-19489 exploitable?
The high-severity memory-overflow flaw can be used by remote unauthenticated actors for denial-of-service attacks when SIP ALG is enabled on a large-scale NAT group configuration.
What action does Citrix recommend?
Citrix urges customers to secure affected NetScaler systems immediately and to patch the flaws as soon as possible.