NetScaler Security Bulletin for CVE-2026-19489 and CVE-2026-19490
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939
The following supported versions of NetScaler ADC and NetScaler Gateway are affected by the vulnerabilities:
- NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
- NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
- NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
| CVE-ID | Description | Pre-conditions | CWE | CVSSv4 |
|---|---|---|---|---|
| CVE-2026-19489 | Memory overflow vulnerability leading to unpredictable behavior or Denial of Service | SIP ALG(Session Initiation Protocol Application Layer Gateway) should be enabled on a Large Scale NAT (LSN) group configuration. | CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer | CVSS v4.0 Base Score: 8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:L/VI:L/VA:H/SC:N/SI:N/SA:L) |
| CVE-2026-19490 | Authentication bypass using an alternate path | The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, subject to the following version-specific requirements: 14.1-43.56 or later: Applicable only when configured with a SAML action. 14.1-43.55 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver 13.1-61.28 or later: Applicable only when configured with a SAML action. 13.1-61.27 or earlier: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver 13.1 FIPS: Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver. | CWE-288: Authentication Bypass Using an Alternate Path | CVSS v4.0 Base Score: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/ VC:H/VI:H/VA:H/SC:L/SI:L/SA:L) |
Steps to determine if an appliance meets the CVE preconditions
For CVE-2026-19489:
Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:
- "add lsn group.*sipalg.*"
For CVE-2026-19490:
Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:
SAML action configuration
- "add authentication samlAction.*"
Auth or VPN vserver
- "add authentication vserver .*"
Or
- "add vpn vserver .*"