Critical NetScaler Flaw Lets Attackers Bypass Authentication

Citrix has issued urgent patches for NetScaler ADC and NetScaler Gateway after discovering two serious security vulnerabilities—one that allows authentication bypass on gateway or AAA servers, the other causing a memory overflow risk in certain configurations. These flaws affect customer-managed NetScaler setups, including specific FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid deployments. Citrix-managed cloud services and Adaptive Authentication are unaffected thanks to pre-applied fixes. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

What the Vulnerabilities Are

The first flaw, tracked as CVE-2026-19489 (CVSS score 8.8), triggers unpredictable behavior or a denial-of-service condition when large scale NAT (LSN) groups use the Session Initiation Protocol Application Layer Gateway (SIP ALG). The second, more severe issue—CVE-2026-19490 (CVSS score 9.3)—enables attackers to bypass authentication entirely under specific conditions. This bypass works when NetScaler is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server and a SAML action is involved, depending on version and configuration. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

Affected Versions & Mitigation Measures

NetScaler ADC and Gateway versions prior to and not including 14.1-73.32 or 13.1-63.21 are vulnerable, as are certain FIPS and NDcPP variants unless updated. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

To verify exposure, administrators should check their configurations: for CVE-2026-19489, see if “lsn group” and “sipalg” are enabled; for CVE-2026-19490, look for SAML action and VPN or AAA virtual server settings. If they’re present, the risk is real. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

Citrix also advises using the Global Deny Lists feature (default-enabled in firmware versions 14.1-60.52, 13.1-63.16 and newer) via NetScaler Console to help mitigate the authentication bypass issue until automatic upgrades can be applied. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

An Urgent Fix & Why This Matters

Patches for all impacted software versions are now available. The safe builds include NetScaler ADC and Gateway 14.1-73.32 or later, 13.1-63.21 or later, plus corresponding FIPS and NDcPP variants. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

The flaws were reported by a penetration tester from JPMorgan Chase. So far, there is no indication of these flaws being exploited in live attacks—but recent history warns that NetScaler vulnerabilities tend to become targets quickly after disclosures. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

Last month, a different input validation vulnerability in NetScaler ADC and Gateway (CVE-2026-8451, CVSS score 8.8) was reportedly targeted in the wild less than 24 hours following public exposure, underscoring the urgency. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

For organizations relying on NetScaler for SSL VPN, remote access, or identity and access management, this could be a critical risk. Missing these patches could mean full bypass of authentication under certain configurations. ([thehackernews.com](https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html))

Analytically speaking, this development highlights how even well-designed access systems remain vulnerable when default or complex features (like SAML actions or specific NAT setups) intersect. The speed with which previous NetScaler flaws have been abused in the wild suggests that any delay in updating could lead to active exploits. It’s a reminder that configuration audits are as essential as patching, particularly for organizations using Gateway, VPN, or AAA services. What to watch for now: whether there are reports of real-world exploitation of CVE-2026-19490, and how fast users and admins adopt the fixed firmware.