Affected Systems
Citrix NetScaler ADC and NetScaler Gateway appliances (all supported versions prior to 14.1-73.32 and 13.1-63.21). CVE-2026-19490 affects appliances configured as AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with SAML authentication. CVE-2026-19489 affects appliances with SIP ALG enabled on large-scale NAT configurations. Includes FIPS and NDcPP builds, and SecurAccess ZTNA Hybrid deployments using customer-managed NetScaler instances.
Exploitation Status
No active exploitation reported. However, Citrix has history of rapid exploitation: two NetScaler vulnerabilities disclosed in March 2026 (CVE-2026-3055, CVE-2026-4368) were exploited within days. CISA has cataloged 22 exploited Citrix vulnerabilities in the past five years, six used in ransomware campaigns. Over 24,000 NetScaler instances currently exposed online per ShadowServer Foundation.
Business Impact
CVE-2026-19490 enables unauthenticated remote attackers to bypass authentication on NetScaler Gateway and AAA virtual servers, potentially granting full access to internal resources protected by these appliances. CVE-2026-19489 allows unauthenticated DoS attacks against NetScaler appliances with SIP ALG enabled, disrupting business-critical load balancing and remote access services. Given Citrix's track record of rapid post-disclosure exploitation and the authentication bypass nature of CVE-2026-19490, expect active exploitation attempts within days to weeks. Federal agencies under CISA jurisdiction should anticipate KEV catalog addition if exploitation emerges.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all NetScaler ADC and Gateway appliances in your environment and check configuration for vulnerable conditions: search for 'add authentication samlAction', 'add authentication vserver', 'add vpn vserver' (CVE-2026-19490), and 'add lsn group.*sipalg' (CVE-2026-19489)
- Upgrade vulnerable NetScaler ADC and Gateway appliances to patched versions: 14.1-73.32 or later, 13.1-63.21 or later, or applicable FIPS/NDcPP builds (14.1-73.32 FIPS, 13.1-37.277)
- Prioritize patching internet-facing NetScaler Gateway instances configured with SAML authentication, as these present the highest risk for CVE-2026-19490 exploitation
- Review NetScaler access logs for anomalous authentication patterns or unexpected successful logins, particularly on SAML-enabled gateways, to detect potential early exploitation attempts
- If immediate patching is not feasible, consider temporary mitigations such as restricting NetScaler management interface access to trusted networks and implementing additional network-layer controls on Gateway access until patches can be applied
