Last week, Citric disclosed a pair of vulnerabilities impacting its NetScaler ADC and NetScaler Gateway devices, and security researchers are urging the company’s customers to take urgent action on one of them.
CVE-2026-19489 and CVE-2026-19490 were disclosed on 19 August, and while the former has a CVSS score of 8.8, the latter has a far more serious rating of 9.3.
While CVE-2026-19489 is a memory overflow vulnerability that could lead to unpredictable behaviour or denial of service, CVE-2026-19490 is an authentication bypass issue, and one that cyber security firm Rapid7 says should be addressed as a priority.
“NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter,” Rapid7 said in a blog post on the same day.
“NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality.
“Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors.”
CVE-2026-19490 (and CVE-2026-19489) impacts the following versions:
- NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21
- NetScaler ADC FIPS: Versions prior to 14.1-73.32 FIPS
- NetScaler ADC FIPS and NDcPP: Versions prior to 13.1-37.277
Citrix also said customers can determine if their systems are impacted by CVE-2026-19490 by inspecting their Netscaler configuration for the following items:
- SAML action configuration is in place:
- “add authentication samlAction.*”
- Auth or VPN vserver is configured:
- “add authentication vserver .*”
- “add vpn vserver .*”
And while no malicious activity targeting CVE-2026-19490 has yet been detected, it’s likely only a matter of time.
“As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild,” Rapid7 said.
“However, organisations should prioritise patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.