Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.

According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments that use customer-managed NetScaler instances.

It bears noting that the vulnerabilities do not apply to Citrix-managed cloud services or Citrix-managed Adaptive Authentication, as the necessary updates have already been applied. The list of impacted NetScaler versions is below -

  • NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
  • NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277

The first of the two vulnerabilities is CVE-2026-19489 (CVSS score: 8.8), a memory overflow vulnerability that may lead to unpredictable behavior or denial-of-service (DoS). However, it applies only when Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT (LSN) group configuration.

CVE-2026-19490 (CVSS score: 9.3), the more severe of the two, is an authentication bypass vulnerability that affects appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, assuming the following version-specific requirements are met -

  • 14.1-43.56 or later - Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
  • 14.1-66.68-FIPS or later - Applicable only when configured with a SAML action AND NetScaler is configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
  • 14.1-43.55 or earlier - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy ) or AAA vserver
  • 13.1-61.28 or later - Applicable only when configured with a SAML action
  • 13.1-61.27 or earlier - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver
  • 13.1 FIPS - Applicable when configured with Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA vserver

"Customers should also review their configurations to determine whether the documented preconditions apply," Citrix said. "Prioritization should be based on exposure, deployment role, and whether the affected configuration is enabled."

For CVE-2026-19489, customers can check if their device meets the precondition by inspecting their NetScaler configuration for the specified string -

  • add lsn group.sipalg.

Similarly, for CVE-2026-19490, customers can verify their NetScaler configuration for the below string -

  • add authentication samlAction.* (SAML action configuration)
  • add authentication vserver . or add vpn vserver . (for AAA or VPN vserver)

"Additionally, this vulnerability can be mitigated by using signatures if you are using NetScaler Console (Service or on-prem) and if the NetScaler firmware version is higher than 14.1-60.52 and 13.1-63.16 or higher, which have a feature called Global Deny Lists that consumes the signatures and automatically applies the signatures to NetScaler appliances managed via NetScaler Console," Citrix said. "The feature is enabled by default."

The updates are available in the following versions -

  • NetScaler ADC and NetScaler Gateway 14.1-73.32 or later
  • NetScaler ADC and NetScaler Gateway 13.1-63.21 or later
  • NetScaler ADC FIPS 14.1-73.32 FIPS or later
  • NetScaler ADC FIPS and NDcPP 13.1-37.277 or later

Citrix has credited Samarth Vashisht from the pen-test team at JPMorgan Chase for discovering and reporting the flaws. Although there is no evidence that the shortcomings have been exploited in the wild, newly disclosed Citrix vulnerabilities have been a lucrative target for attackers.

Last month, an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway (CVE-2026-8451, CVSS score: 8.8) witnessed active exploitation efforts less than 24 hours of public disclosure.