2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Cybersecurity Classified by Officially
Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) [1].
CERT-EU recommends updating affected devices as soon as possible.
The vulnerability CVE-2026-19489 (CVSS: 8.8) is a memory overflow vulnerability that can lead to unpredictable behaviour or Denial of Service.
The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path.
The following supported versions of NetScaler ADC and NetScaler Gateway are affected:
The vulnerability CVE-2026-19489 requires SIP ALG(Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration.
Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:
The vulnerability CVE-2026-19490 requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. On versions 14.1-43.56 or later and 13.1-61.28 or later, the issue is applicable only when a SAML action is configured; on earlier builds and 13.1 FIPS, Gateway or AAA virtual server configuration is sufficient.
Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:
add authentication vserver .* OR add vpn vserver .* CERT-EU recommends to install the relevant updated versions on affected devices as soon as possible [1].
This is an extract. The publication continues at the source.
Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-010/
Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT-EU — imported from official source
- Official source
- https://www.cert.europa.eu/publications/security-advisories-rss RSS
- Imported
- September 15, 2026 20:57
- Versions
- 1 recorded
- Identity
security-advisories-10947