Cloud Software Group has flagged two major security flaws in NetScaler ADC and NetScaler Gateway appliances that let attackers bypass authentication without credentials or cause denial-of-service (DoS) disruptions. Tracked as CVE-2026-19490 and CVE-2026-19489, these vulnerabilities pose a serious threat to enterprise remote access infrastructure. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
What the Flaws Are
The more critical issue, CVE-2026-19490, has a CVSS v4.0 base score of 9.3 and is classified under authentication bypass via an alternate path (CWE-288). It allows attackers to circumvent authentication entirely on systems where NetScaler acts as a Gateway for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
Whether the vulnerability can be exploited depends on the software version installed. On newer builds—NetScaler 14.1-43.56 and later, or 13.1-61.28 and beyond—the appliance needs a SAML action configured for the flaw to be leveraged. Older versions with any Gateway or AAA vserver configuration are vulnerable without additional conditions. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
The second vulnerability, CVE-2026-19489, rates 8.8 on the CVSS v4.0 scale and is caused by a memory overflow issue (CWE-119) linked to Session Initiation Protocol application-layer gateway (SIP ALG) when used inside a Large Scale NAT (LSN) group. Exploiting this can lead to erratic appliance behavior or a full DoS, disrupting critical network services. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
Which Versions are Impacted & How to Check
The affected versions include NetScaler ADC and Gateway 14.1 before build 73.32, version 13.1 before build 63.21, and their FIPS and NDcPP variants. Secure Private Access Hybrid setups using customer-managed NetScaler instances are also at risk. Cloud-based services by the vendor have been patched already. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
To assess exposure, administrators need to inspect configuration files: look for LSN group entries with SIP ALG enabled for the memory overflow bug (CVE-2026-19489), and check for SAML action or any authentication/VPN virtual server entries for the bypass flaw (CVE-2026-19490). ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
Mitigation & Urgency
Cloud Software Group advises all users to immediately upgrade to NetScaler ADC or Gateway version 14.1-73.32 or later, or 13.1-63.21 or newer. Updated builds include fixes for both vulnerabilities, including the FIPS/NDcPP variants. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
Due to the exposure of these appliances to public networks and the low complexity required for attacks, patching should not be delayed or treated as routine. Delays are especially risky once detailed exploit information becomes public. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
The flaws were reported through responsible disclosure by a penetration tester from JPMorgan Chase, highlighting the importance of coordinated vulnerability research for protecting widespread enterprise components. ([cybersecuritynews.com](https://cybersecuritynews.com/critical-citrix-netscaler-vulnerability/))
What this means: Organizations relying on NetScaler ADC or Gateway features—especially those providing remote access—are facing immediate risk. The authentication bypass allows entry without valid credentials under certain builds; so even well-configured networks could be vulnerable. The memory overflow issue can disrupt operations entirely. Moving quickly to updated versions and auditing system configurations are essential defenses.