2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
ID: f8e58129-f5f1-5f60-bf9d-39946ecddecf
STIX ID: report--f8e58129-f5f1-5f60-bf9d-39946ecddecf
Feed Name: CERT-EU Security Advisories
On 19 August 2026 CERT-EU relays a Citrix security advisory for NetScaler ADC/Gateway describing two critical vulnerabilities: CVE-2026-19489 (memory overflow, CVSS 8.8, potential DoS) and CVE-2026-19490 (authentication bypass, CVSS 9.3). The advisory lists affected 13.1 and 14.1 branches (including FIPS builds), notes specific configuration preconditions (SIP ALG on LSN groups for CVE-2026-19489; Gateway/AAA vserver or SAML action for CVE-2026-19490), and recommends installing the provided updates as soon as possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
