Skip to content
Cybersecurity Advisories

Cybersecurity Advisories

Ncsa.Qa September 10, 2026

Citrix published a security bulletin addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway, rated Critical and High. Successful exploitation may allow remote attackers to bypass login protections or disrupt services. Notably, this was the second Citrix update in the last three months addressing a vulnerability with an exploit confirmed in the wild, following the update reported in the Risk Directive (RD202600097).

The first vulnerability, tracked as CVE-2026-19490, is an authentication bypass vulnerability (CWE-288) with a CVSS v4.0 base score of 9.3 (Critical). Successful exploitation may allow an unauthenticated remote attacker to bypass authentication on appliances configured as a Gateway or a AAA virtual server. A configured SAML action is an additional prerequisite for certain builds. No user interaction is required. The second vulnerability, tracked as CVE-2026-19489, is a memory buffer overflow vulnerability (CWE-119) with a CVSS v4.0 base score of 8.8 (High). Successful exploitation may cause unpredictable behavior or denial of service. Exploitation requires SIP ALG to be enabled on a Large Scale NAT (LSN) group, but does not require authentication or user interaction. CISA has confirmed exploitation of CVE-2026-19490 in the wild and added it to the Known Exploited Vulnerabilities (KEV) catalog on 9 September 2026, reinforcing the need to prioritize remediation.

Citrix have released security updates that address the vulnerabilities described in this Risk Directive. Organizations are advised to keep software up-to-date with latest security patches to mitigate the risk associated with vulnerabilities.

We use cookies to enhance your experience on our website. Click 'Accept All' to consent.