u/zyphaz

▲ 24 r/Citrix

NetScaler Security Bulletin for CVE-2026-19489 and CVE-2026-19490

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities: 

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
  • NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
CVE-ID Description Pre-conditions CWE CVSSv4
CVE-2026-19489 Memory overflow vulnerability leading to unpredictable behavior or Denial of Service SIP ALG(Session Initiation Protocol Application Layer Gateway) should be enabled on a Large Scale NAT (LSN) group configuration. CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer CVSS v4.0 Base Score: 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:L/VI:L/VA:H/SC:N/SI:N/SA:L)
CVE-2026-19490 Authentication bypass using an alternate path The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, subject to the following version-specific requirements: 14.1-43.56 or later: Applicable only when configured with a SAML action. 14.1-43.55 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver 13.1-61.28 or later: Applicable only when configured with a SAML action. 13.1-61.27 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy)  or AAA vserver 13.1 FIPS: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver. CWE-288: Authentication Bypass Using an Alternate Path CVSS v4.0 Base Score: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)

Steps to determine if an appliance meets the CVE preconditions

For CVE-2026-19489:

Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:

  • "​add lsn group.*sipalg.*"

 

For CVE-2026-19490: 

Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:

SAML action configuration

  • "add authentication samlAction.*"

 Auth or VPN vserver

  •  "add authentication vserver .*"

Or 

  •  "add vpn vserver .*"
reddit.com
u/zyphaz — 20 hours ago