logo

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

ID: 1c855198-76ac-598b-b171-fc0ad6610368

STIX ID: report--1c855198-76ac-598b-b171-fc0ad6610368

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Sinisa Markovic

...
...

Citrix has released patches for two critical NetScaler ADC/NetScaler Gateway vulnerabilities — CVE-2026-19490 (authentication bypass, CVSS 9.3) and CVE-2026-19489 (memory overflow, CVSS 8.8) — affecting specific 13.1 and 14.1 builds; the advisory describes narrow preconditions (Gateway/AAA roles, SAML actions, SIP ALG with LSN), provides configuration checks and mitigations (including Global Deny Lists and signatures via NetScaler Console), and urges immediate upgrade of affected appliances while noting marketplace images had not yet been refreshed and Rapid7 had not observed exploitation as of 19 Aug 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.