Advisories
Citrix NetScaler ADC & Gateway Hit by Dual Critical Flaws – Patch Urgently
Citrix has disclosed two critical security issues in its NetScaler ADC and Gateway appliances. CVE‑2026‑19489 (memory overflow) can trigger DoS when SIP ALG is active on a Large‑Scale NAT group, while CVE‑2026‑19490 (auth bypass) targets Gateway or AAA virtual servers with SAML actions. Affected builds span 13.1 and 14.1 releases, including FIPS variants. CERT‑EU urges all users to apply the latest updates immediately and verify configuration strings to assess risk.
What’s at Stake
Citrix’s NetScaler ADC and Gateway are core components for many enterprises’ application delivery and VPN infrastructure. Two newly identified CVEs—CVE‑2026‑19489 and CVE‑2026‑19490—carry high CVSS scores (8.8 and 9.3 respectively) and can lead to denial‑of‑service or unauthorized access if left unpatched.Technical Details
- CVE‑2026‑19489 – A memory overflow that may crash the appliance or produce unpredictable behaviour. The flaw is exploitable only when
SIP ALGis enabled on aLarge Scale NAT (LSN)group. - CVE‑2026‑19490 – An authentication bypass that allows attackers to reach the Gateway or AAA virtual server without credentials. The issue surfaces when a
SAML actionis configured on a Gateway or AAA vserver.
Affected Versions
- NetScaler ADC & Gateway 14.1 prior to 14.1‑73.32
- NetScaler ADC & Gateway 13.1 prior to 13.1‑63.21
- NetScaler ADC FIPS 14.1‑73.32 and earlier
- NetScaler ADC FIPS & NDcPP 13.1‑37.277 and earlier
Pre‑conditions to Check
- For CVE‑2026‑19489: Search the appliance configuration for
add lsn group.*sipalg.*. If present, the device is vulnerable. - For CVE‑2026‑19490: Verify the presence of
add authentication samlAction.*oradd authentication vserver .*/add vpn vserver .*. On builds 14.1‑43.56+ or 13.1‑61.28+, the flaw applies only when a SAML action is defined; on earlier builds or 13.1 FIPS, any Gateway or AAA vserver configuration suffices.
Mitigation & Action Items
- Apply the latest Citrix patches that address CVE‑2026‑19489 and CVE‑2026‑19490.
- Confirm the absence of the identified configuration strings if you cannot patch immediately.
- Disable
SIP ALGon LSN groups or remove unnecessary SAML actions as a temporary workaround. - Notify your security team and document the remediation steps for compliance audits.
“CERT‑EU recommends updating affected devices as soon as possible to eliminate the risk of denial‑of‑service or unauthorized access.”