Overview
- Citrix published fixes on Thursday for two NetScaler ADC and NetScaler Gateway vulnerabilities, naming the authentication bypass as CVE-2026-19490 and a memory overflow/DoS as CVE-2026-19489.
- CVE-2026-19490 lets a remote, unauthenticated attacker bypass login checks on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server when specific SAML or version conditions are met.
- CVE-2026-19489 is a separate high‑severity memory overflow that can cause crashes or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group, a narrow configuration precondition.
- Citrix published exact fixed builds (for example 14.1-73.32 and 13.1-63.21), offered configuration checks administrators can run (for example searching for add authentication samlAction or add lsn group.*sipalg.*), and said Citrix‑managed cloud services are already updated while customer‑managed appliances must be patched.
- Researchers say there are no confirmed in‑the‑wild exploits yet but warn exploit attempts are likely because thousands of NetScaler instances are internet‑exposed; administrators should apply the recommended builds, verify configurations, and expect possible rapid abuse.