AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1

Imported from official source

Cybersecurity Classified by Officially

Number: AL26-019
Date: September 4, 2026
Updated: September 9, 2026

Audience

This Alert is intended for IT professionals and managers.

Purpose

An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.

Details

The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway)Footnote 1.  

In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026Footnote 2.

Tracked as CVE-2026-19490Footnote 3, this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288)Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.

Tracked as CVE-2026-19489Footnote 5, this vulnerability is a Classic Buffer Overflow vulnerability (CWE-120)Footnote 6. This vulnerability may allow memory overflow leading to unpredictable behavior or Denial of Service conditions.

Pre-conditions for these vulnerabilities are that the NetScaler ADC or NetScaler Gateway 14.1-43.56 and later, as well as 13.1-61.28 and later, must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider).

Earlier builds with Gateway or AAA configuration are also vulnerable.

To determine if organizations are impacted, it is recommended to check if the appliance meets the precondition by inspecting the NetScaler configuration for the specified strings:

For CVE-2026-19489:

"add lsn group.*sipalg.*"

For CVE-2026-19490:

SAML action configuration:

"add authentication samlAction.*"

Auth or VPN vserver:

This is an extract. The publication continues at the source.

Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489

Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Canadian Centre for Cyber Security — imported from official source
Official source
https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-nets...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.