Source: Help Net Security
Author: Sinisa Markovic
URL: https://www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/
ONE SENTENCE SUMMARY:
Citrix patched critical NetScaler authentication bypass and high-severity overflow flaws, urging rapid upgrades and configuration checks to prevent likely exploitation.
MAIN POINTS:
- Citrix released fixes for two NetScaler ADC/Gateway vulnerabilities and urged immediate upgrades.
- CVE-2026-19490 enables authentication bypass via an alternate path under specific configurations.
- Gateway roles affected include SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual servers.
- Exposure depends on firmware versions and whether a SAML action is configured.
- Older firmware can be vulnerable with Gateway/AAA configuration alone, without SAML setup.
- Precondition checks include searching configs for samlAction, authentication vserver, and vpn vserver.
- NetScaler Console Global Deny Lists can mitigate via signatures on sufficiently new firmware.
- CVE-2026-19489 is a memory overflow causing DoS/unpredictable behavior when SIP ALG on LSN.
- Affected versions include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21.
- After upgrading ICA proxy, older session-ticket reconnects are dropped, requiring relaunch.
TAKEAWAYS:
- Prioritize emergency patching because NetScaler flaws historically see rapid post-disclosure exploitation.
- Validate real exposure by confirming Gateway/AAA usage and SAML-related configuration conditions.
- Assess SIP ALG within Large Scale NAT groups to determine risk from the overflow vulnerability.
- Plan for user impact in ICA proxy environments due to forced session relaunch after upgrades.
- Verify cloud marketplace images separately, since AWS/Azure/GCP listings may lag behind patched builds.