CVE Tools
Back to feed
Patch released Citrix NetScaler ADC auth-bypass Citrix NetScaler Gateway Citrix network-edge

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Help Net Security·By Sinisa Markovic··3 min read
CVE Tools coverage

Citrix has issued urgent security updates for NetScaler ADC and NetScaler Gateway to address two newly disclosed vulnerabilities, with the primary threat being CVE-2026-19490. This critical flaw carries a CVSS v4.0 score of 9.3 and permits attackers to bypass authentication mechanisms under specific configuration conditions involving Gateway or AAA virtual servers. A secondary issue, CVE-2026-19489 (CVSS 8.8), involves a memory overflow that could lead to denial of service when SIP ALG is enabled on Large Scale NAT groups. While Rapid7 reports no evidence of active exploitation as of mid-August, Citrix advises immediate upgrades to supported builds, specifically versions 14.1-73.32 and 13.1-63.21, given the high likelihood of rapid opportunistic attacks against exposed infrastructure.