Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490)

Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490)

By SystemTek – Technology news and information
Publication Date: 2026-09-02 07:30:00

Security teams are being urged to update Citrix NetScaler appliances after two vulnerabilities were disclosed that could allow attackers to bypass authentication or cause systems to crash.

The vulnerabilities, tracked as CVE-2026-19489 and CVE-2026-19490, affect NetScaler ADC and NetScaler Gateway, products widely used to provide application delivery, remote access and VPN services.

CVE-2026-19489 is a memory overflow vulnerability with a CVSS 4.0 score of 8.8. The flaw can result in unpredictable behaviour and denial-of-service conditions. It requires SIP ALG to be enabled on a Large Scale NAT (LSN) group configuration.

The more serious of the two vulnerabilities is CVE-2026-19490, which has a CVSS 4.0 score of 9.3 (Critical). The vulnerability is an authentication bypass using an alternate path, potentially allowing a remote, unauthenticated attacker to bypass authentication and gain access to protected services.

The vulnerability is particularly concerning because…