Citrix has released patches for two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication bypass that security researchers expect to be exploited in the wild soon.
The Critical Flaw
The more severe issue, tracked as CVE-2026-19490 (CVSS 9.3), is an authentication bypass using an alternative path. It affects NetScaler appliances configured as a gateway, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy setups, as well as those configured as an AAA virtual server. According to cybersecurity firm Rapid7, the flaw can be exploited remotely by unauthenticated attackers with no user interaction required.
Affected versions include NetScaler ADC and Gateway builds 14.1-43.56 and later, 14.1-66.68-FIPS and later, 14.1-43.55 and earlier, 13.1-61.28 and later, 13.1-61.27 and earlier, and 13.1 FIPS.
Second Bug: Memory Overflow DoS Risk
Citrix also patched CVE-2026-19489, a high-severity memory overflow vulnerability that can trigger unexpected behavior or denial-of-service conditions when SIP ALG is enabled within an LSN group configuration.
Fixes for both issues are included in NetScaler ADC and Gateway versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS/13.1-NDcPP 13.1-37.277. Citrix noted that Secure Private Access Hybrid deployments using NetScaler instances are also affected and require upgrading to the recommended builds.
Why This Matters
Rapid7 says there is currently no evidence of active exploitation of the authentication bypass, but stressed that NetScaler’s position at the network perimeter makes it a high-value target. NetScaler ADC handles application delivery, traffic management, load balancing, SSL/TLS offloading, and application security, while NetScaler Gateway provides secure remote access and VPN functionality, both commonly exposed at enterprise DMZ boundaries.
Given the history of rapid exploitation against Citrix products following disclosure, Rapid7 is urging organizations to prioritize patching affected systems on an emergency basis rather than waiting for a scheduled maintenance window.
- Identify all NetScaler ADC and Gateway instances, including those in Secure Private Access Hybrid deployments
- Upgrade to the fixed builds: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-FIPS/13.1-NDcPP 13.1-37.277
- Treat patching as urgent given the appliances’ typical internet-facing exposure
