CVE Tools

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Help Net SecurityBy Sinisa Markovic

PatchCitrix NetScaler ADCCitrix NetScaler Gateway

Our summary

Citrix has issued urgent security updates for NetScaler ADC and NetScaler Gateway to address two newly disclosed vulnerabilities, with the primary threat being CVE-2026-19490. This critical flaw carries a CVSS v4.0 score of 9.3 and permits attackers to bypass authentication mechanisms under specific configuration conditions involving Gateway or AAA virtual servers. A secondary issue, CVE-2026-19489 (CVSS 8.8), involves a memory overflow that could lead to denial of service when SIP ALG is enabled on Large Scale NAT groups. While Rapid7 reports no evidence of active exploitation as of mid-August, Citrix advises immediate upgrades to supported builds, specifically versions 14.1-73.32 and 13.1-63.21, given the high likelihood of rapid opportunistic attacks against exposed infrastructure.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store