Affected Systems

Citrix NetScaler ADC and NetScaler Gateway customer-managed instances: versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, FIPS builds before 14.1-73.32 FIPS and 13.1-37.277. Affects appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers. CVE-2026-19490 requires SAML action configuration in some versions. CVE-2026-19489 affects only LSN deployments with SIP ALG enabled. Citrix-managed cloud services are not affected.

Exploitation Status

No evidence of active exploitation reported. However, Citrix vulnerabilities historically exploited within 24 hours of disclosure (e.g., CVE-2026-8451 in July 2026). PoC status unknown.

Business Impact

CVE-2026-19490 (CVSS 9.3) allows authentication bypass on Gateway and AAA servers, enabling unauthorized access to VPN, remote desktop, and authentication infrastructure. CVE-2026-19489 (CVSS 8.8) causes memory overflow leading to DoS on LSN configurations with SIP ALG. Remote access infrastructure compromise can lead to lateral movement, data exfiltration, and persistent access. Organizations using SAML authentication with NetScaler Gateway face elevated risk.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately patch customer-managed NetScaler ADC and Gateway to 14.1-73.32, 13.1-63.21, or later (FIPS: 14.1-73.32 FIPS, 13.1-37.277)
  • Verify exposure to CVE-2026-19490 by checking NetScaler config for 'add authentication samlAction' and 'add authentication vserver' or 'add vpn vserver' strings
  • Enable Global Deny Lists via NetScaler Console (on-prem or Service) for versions 14.1-60.52+ or 13.1-63.16+ as interim mitigation
  • Review authentication logs for anomalous Gateway/AAA access patterns, especially SAML-based sessions, from August 2026 onward
  • For CVE-2026-19489, check LSN configurations for 'add lsn group.*sipalg.*' and disable SIP ALG if not required