CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical NetScaler Authentication Bypass Flaw Patched by Citrix

August 20, 2026

Citrix has released security updates to address two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw that could allow attackers to bypass authentication on certain Gateway and AAA server configurations.

The most severe issue, tracked as CVE-2026-19490 (CVSS score: 9.3), is an authentication bypass vulnerability. It affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, with specific version-dependent preconditions. In some versions, the flaw is only exploitable when a SAML action is configured. Citrix advises customers to review their configurations to determine if they meet the documented preconditions.

The second vulnerability, CVE-2026-19489 (CVSS score: 8.8), is a memory overflow issue that could lead to unpredictable behavior or denial-of-service (DoS). It only applies when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT (LSN) group configuration.

Affected versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and NetScaler ADC FIPS and NDcPP before 13.1-37.277. The vulnerabilities do not affect Citrix-managed cloud services or Citrix-managed Adaptive Authentication, as updates have already been applied.

Citrix has provided configuration strings for customers to check if their devices are affected. For CVE-2026-19489, they can look for ‘add lsn group.*sipalg.*’ in the configuration. For CVE-2026-19490, they can check for ‘add authentication samlAction.*’ or ‘add authentication vserver .*’ or ‘add vpn vserver .*’. Additionally, mitigation is possible using signatures via NetScaler Console (Service or on-prem) if the firmware version is higher than 14.1-60.52 or 13.1-63.16, which includes a Global Deny Lists feature enabled by default.

The flaws were discovered and reported by Samarth Vashisht from the pen-test team at JPMorgan Chase. While there is no evidence of active exploitation yet, Citrix vulnerabilities have been a lucrative target for attackers. Last month, CVE-2026-8451, an input validation flaw in NetScaler ADC and NetScaler Gateway, was exploited within 24 hours of disclosure.

Citrix strongly recommends that customers apply the available updates immediately and review their configurations to mitigate potential risks.

CVEs: CVE-2026-19490, CVE-2026-19489, CVE-2026-8451

Companies: Citrix, JPMorgan Chase

Products: NetScaler ADC, NetScaler Gateway, NetScaler Console