{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-010.pdf"
    },
    "title": "Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway",
    "serial_number": "2026-010",
    "publish_date": "19-08-2026 16:13:47",
    "description": "On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).<br>\nCERT-EU recommends updating affected devices as soon as possible.<br>\n",
    "url_title": "2026-010",
    "content_markdown": "---    \ntitle: 'Critical Vulnerabilities in\u00a0Citrix\u00a0NetScaler\u00a0ADC and\u00a0NetScaler\u00a0Gateway'\nnumber: '2026-010'\nversion: '1.0'\noriginal_date: '2026-08-19'\ndate: '2026-08-19'\n---\n\n_History:_\n\n* _19/08/2026 --- v1.0 -- Initial publication_\n\n# Summary\n\nOn 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) [1].\n\nCERT-EU recommends updating affected devices as soon as possible.\n\n# Technical Details\n\nThe vulnerability **CVE-2026-19489** (CVSS: 8.8) is a memory overflow vulnerability that can lead to unpredictable behaviour or Denial of Service.\n\nThe vulnerability **CVE-2026-19490** (CVSS: 9.3) is an authentication bypass using an alternate path.\n\n# Affected Products\n\nThe following supported versions of NetScaler ADC and NetScaler Gateway are affected:\n\n* NetScaler ADC and NetScaler Gateway version 14.1 before 14.1-73.32\n* NetScaler ADC and NetScaler Gateway version 13.1 before 13.1-63.21\n* NetScaler ADC FIPS before 14.1-73.32 FIPS\n* NetScaler ADC FIPS and NDcPP before 13.1-37.277\n\nThe vulnerability CVE-2026-19489 requires SIP ALG(Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration. \n\nCustomers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:\n\n```\nadd lsn group.*sipalg.*\n```\n\nThe vulnerability CVE-2026-19490 requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. On versions 14.1-43.56 or later and 13.1-61.28 or later, the issue is applicable only when a SAML action is configured; on earlier builds and 13.1 FIPS, Gateway or AAA virtual server configuration is sufficient.\n\nCustomers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:\n\n**SAML action configuration**:\n\n```\nadd authentication samlAction.*\n```\n\n**Auth or VPN vserver**:\n\n```\nadd authentication vserver .*\n\nOR\n\nadd vpn vserver .*\n```\n\n# Recommendations\n\nCERT-EU recommends to install the relevant updated versions on affected devices as soon as possible [1]. \n\n# References\n\n[1] <https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939>",
    "content_html": "<p><em>History:</em></p><ul><li><em>19/08/2026 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) [1].</p><p>CERT-EU recommends updating affected devices as soon as possible.</p><h2 id=\"technical-details\">Technical Details</h2><p>The vulnerability <strong>CVE-2026-19489</strong> (CVSS: 8.8) is a memory overflow vulnerability that can lead to unpredictable behaviour or Denial of Service.</p><p>The vulnerability <strong>CVE-2026-19490</strong> (CVSS: 9.3) is an authentication bypass using an alternate path.</p><h2 id=\"affected-products\">Affected Products</h2><p>The following supported versions of NetScaler ADC and NetScaler Gateway are affected:</p><ul><li>NetScaler ADC and NetScaler Gateway version 14.1 before 14.1-73.32</li><li>NetScaler ADC and NetScaler Gateway version 13.1 before 13.1-63.21</li><li>NetScaler ADC FIPS before 14.1-73.32 FIPS</li><li>NetScaler ADC FIPS and NDcPP before 13.1-37.277</li></ul><p>The vulnerability CVE-2026-19489 requires SIP ALG(Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration. </p><p>Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:</p><pre><code>add lsn group.*sipalg.*\n</code></pre><p>The vulnerability CVE-2026-19490 requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. On versions 14.1-43.56 or later and 13.1-61.28 or later, the issue is applicable only when a SAML action is configured; on earlier builds and 13.1 FIPS, Gateway or AAA virtual server configuration is sufficient.</p><p>Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string:</p><p><strong>SAML action configuration</strong>:</p><pre><code>add authentication samlAction.*\n</code></pre><p><strong>Auth or VPN vserver</strong>:</p><pre><code>add authentication vserver .*\n\nOR\n\nadd vpn vserver .*\n</code></pre><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU recommends to install the relevant updated versions on affected devices as soon as possible [1]. </p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939\">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}