Published: Tue 8 September 2026
Prepared by: Brandon Sawyer, Vulnerability Analyst
Purpose
On 19 August 2026, Citrix (Cloud Software Group) disclosed two vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances, assigned CVE-2026-19489 and CVE-2026-19490. The more severe of the two, CVE-2026-19490, is a critical authentication bypass vulnerability that allows a remote, unauthenticated attacker to bypass authentication controls on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. The second, CVE-2026-19489, is a high-severity memory overflow vulnerability that can be exploited by an unauthenticated attacker to cause unpredictable behaviour or denial of service. On 4 September 2026, the Australian Cyber Security Centre (ACSC) released an alert raising awareness of this vulnerability pair and urging Australian organisations to treat patching as a priority, noting that NetScaler appliances are commonly deployed as internet-facing edge devices and are a frequent target for threat actors seeking initial access into corporate networks. A working proof-of-concept (PoC) for CVE-2026-19490 became publicly available around 3 September 2026, and threat intelligence sensors have since recorded exploitation attempts against internet-facing NetScaler appliances, including within Australia. Security teams should prioritise patching affected systems to the recommended builds immediately.
Vulnerability Details
CVE-2026-19489
CVE-2026-19489 is a memory overflow vulnerability (CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer) in NetScaler ADC and NetScaler Gateway that can lead to unpredictable appliance behaviour or denial of service. It carries a CVSSv4.0 base score of 8.8 (High). The vulnerability applies where SIP ALG (Session Initiation Protocol Application Layer Gateway) is enabled on a Large Scale NAT (LSN) group configuration. It affects NetScaler ADC and NetScaler Gateway 14.1 releases before 14.1-73.32, 13.1 releases before 13.1-63.21, and the corresponding FIPS and NDcPP builds.
CVE-2026-19490
CVE-2026-19490 is an authentication bypass vulnerability (CWE-288: Authentication Bypass Using an Alternate Path) in NetScaler ADC and NetScaler Gateway that allows a remote, unauthenticated attacker to bypass authentication controls with no user interaction and no valid credentials required. It carries a CVSSv4.0 base score of 9.3 (Critical). The vulnerability applies where the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, with the precise pre-conditions varying by build:
- 14.1-43.56 or later, and 14.1-66.68-FIPS or later: applicable only where a SAML action is configured, in addition to a Gateway or AAA vserver.
- 14.1-43.55 or earlier: applicable wherever a Gateway or AAA vserver is configured (SAML action not required).
- 13.1-61.28 or later: applicable only where a SAML action is configured.
- 13.1-61.27 or earlier, and 13.1 FIPS: applicable wherever a Gateway or AAA vserver is configured.
Because NetScaler Gateway is frequently deployed at the network edge to provide SSL VPN and remote access services, successful exploitation could allow an attacker to reach protected internal services without valid credentials, representing a direct path to initial access.
Relationship Between the Two CVEs
CVE-2026-19489 and CVE-2026-19490 are distinct vulnerabilities affecting different NetScaler components (LSN/SIP ALG versus the Gateway/AAA authentication path) and were disclosed together in the same Citrix security bulletin (CTX696939). They do not share a root cause, but both are remotely exploitable without authentication, and both are addressed by the same set of upgraded builds. Citrix has confirmed no workarounds or mitigating configurations are available for either issue; upgrading is the only remediation path.
Discovery and Disclosure Timeline
| Date | Event |
| 19 Aug 2026 | Citrix publishes security bulletin CTX696939; patched builds released for both CVEs |
| 20 Aug 2026 | Security media (BleepingComputer, SecurityWeek, The Hacker News) report on the vulnerabilities; no exploitation observed at time of reporting |
| 3 Sept 2026 | A public proof-of-concept (PoC) for CVE-2026-19490 becomes available; threat intelligence firm Previdian begins recording exploitation attempts against sensor infrastructure within 24 hours |
| 4 Sept 2026 | ACSC releases alert urging Australian organisations to prioritise patching CVE-2026-19489 and CVE-2026-19490; The Hacker News updates its coverage to reflect confirmed exploitation attempts against CVE-2026-19490 |
| 6 Sept | Previdian reports exploitation attempts continuing, with activity observed as recently as this date |
| Ongoing | Exploitation attempts against CVE-2026-19490 continue to be monitored; no confirmed successful compromise reported to date. No exploitation activity reported against CVE-2026-19489 |
Impact
Successful exploitation of CVE-2026-19490 grants a remote, unauthenticated attacker the ability to bypass authentication on affected Gateway or AAA virtual servers, effectively the same access a legitimate authenticated user would have to SSL VPN, ICA Proxy, CVPN, or RDP Proxy services fronted by the appliance. Because NetScaler Gateway is typically deployed at the network perimeter to provide remote access into corporate environments, authentication bypass at this layer converts directly into a foothold inside the network, without the attacker needing to steal or guess any credentials.
Successful exploitation of CVE-2026-19489 can cause unpredictable behaviour or denial of service on affected appliances where SIP ALG is enabled on an LSN group, disrupting availability of services relying on that NetScaler instance. SecurAccess ZTNA Hybrid deployments (formerly Secure Private Access Hybrid) that use customer-managed NetScaler instances are also affected by both vulnerabilities and require the same upgrade.
Threat Context
A working proof-of-concept (PoC) for CVE-2026-19490 was released publicly around 3 September 2026, roughly two weeks after Citrix's original patch. Within 24 hours, threat intelligence firm Previdian (formerly KEV Intelligence) began recording exploitation attempts against its sensor network, and continued observing activity through at least 6 September 2026. Reported figures are:
- 10 exploitation attempts observed
- 6 unique attacker IP addresses
- 4 countries of origin: Australia, Germany, Japan, and the United States
Previdian rates this "active exploitation observed" at medium confidence, based on first-party sensor telemetry matching known exploitation patterns for CVE-2026-19490. Separately, the Centre for Cybersecurity Belgium (CCB) issued an urgent warning around the same time urging organisations to patch immediately.
Importantly, this activity has not yet been confirmed to represent successful compromise of real-world systems. Previdian's founder has stated the telemetry provides evidence of exploitation attempts, but does not confirm that any target system was actually breached. CVE-2026-19490 is also not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalogue, and neither Citrix nor the ACSC has published indicators of compromise as at the date of this bulletin.
This should be treated as the vulnerability moving from a theoretical to an actively targeted risk. The presence of attacker source IPs in Australia specifically means Australian-hosted or Australian-facing NetScaler appliances are within the current attack surface being probed, not merely a hypothetical future risk. Organisations that have not yet patched should treat this as materially more urgent than the position at initial disclosure, and should assume opportunistic scanning and exploitation attempts are ongoing against any unpatched, internet-facing appliance meeting the CVE-2026-19490 pre-conditions.
Mitigation
Primary Remediation
The primary remediation is to patch all customer-managed NetScaler ADC and NetScaler Gateway instances to the following builds or later, as applicable:
- NetScaler ADC and NetScaler Gateway 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1-63.21
- NetScaler ADC FIPS 14.1-73.32-FIPS
- NetScaler ADC FIPS and NDcPP 13.1-37.277
Citrix-managed cloud services and Citrix-managed Adaptive Authentication are patched directly by Cloud Software Group and do not require customer action. SecurAccess ZTNA Hybrid deployments using customer-managed NetScaler instances must be upgraded to the recommended builds by the customer.
Compensating Controls
Citrix has confirmed that no workarounds or mitigating configurations are available for either CVE-2026-19489 or CVE-2026-19490. Where immediate patching is not possible, organisations should consider the following interim risk-reduction measures while an upgrade window is arranged:
- Restrict administrative and management-plane access to NetScaler appliances to trusted IP ranges only.
- Where CVE-2026-19489 pre-conditions are met (SIP ALG enabled on an LSN group) and the feature is not business-critical, consider disabling SIP ALG on the affected LSN group as a temporary risk reduction.
- Increase monitoring of authentication logs on affected Gateway and AAA virtual servers for anomalous activity pending patching.
These measures reduce exposure only. They do not address the underlying vulnerabilities, and patching should remain the immediate priority.
Hardening and Longer-Term Actions
Organisations should confirm which NetScaler ADC and NetScaler Gateway instances are deployed across their environment (including those managed by third parties), record current firmware versions, and check configurations against the pre-conditions described below as part of standard vulnerability management practice. Given the recurring history of NetScaler vulnerabilities being weaponised for initial access and, in some cases, ransomware deployment, organisations should ensure NetScaler patching is fast-tracked within change management processes rather than following standard patch cycles, and should continue monitoring Citrix's security bulletin channel and ACSC advisories for updates.
Detection
Determining Exposure (Pre-Condition Checks)
Before patching, organisations can determine whether a given appliance meets the pre-conditions for either vulnerability by reviewing the NetScaler configuration (ns.conf or equivalent) for the following strings:
CVE-2026-19489 (SIP ALG enabled on an LSN group):
add lsn group.*sipalg.*
CVE-2026-19490 (SAML action configuration):
add authentication samlAction.*
CVE-2026-19490 (Auth or VPN virtual server):
add authentication vserver .* add vpn vserver .*
The presence of any of these strings, combined with an affected version, indicates the appliance meets the pre-conditions for exploitation and should be prioritised for patching.
Indicators of Compromise (IOCs)
Exploitation attempts against CVE-2026-19490 have been observed via third-party sensor telemetry, but neither Citrix, the ACSC, nor the sensor provider has published specific file-based, log-pattern, or network IOCs suitable for direct organisational hunting at the time of writing. Attacker IP indicators from Previdian's telemetry are understood to be available to paying subscribers of that service only, and have not been independently verified or reproduced in this bulletin. No IOCs have been published for CVE-2026-19489, and no exploitation activity has been reported against it.
Recommended Detection and Hunting Activities
No exploitation of CVE-2026-19490 was reported before 3 September 2026, when sensor-based detection first began. Organisations that patched at or shortly after the 19 August release therefore appear to have a low likelihood of exposure to currently known activity, though this reflects an absence of reported evidence rather than a guarantee. The guidance below is most relevant to organisations that have not yet patched or had a window of exposure between 19 August and remediation. For those patched early, it can be treated as a precautionary check rather than a response to a known indicator.
With that context in mind, the following activities help confirm whether an appliance has been targeted, and are worth running regardless of patch timing:
- Review NetScaler authentication logs on affected Gateway and AAA virtual servers for anomalous or unexpected authentication events, particularly since 3 September 2026, when exploitation attempts were first observed.
- Review SAML-related authentication logs where a SAML action is configured, for unexpected assertions or authentication flows.
- Monitor for unexpected configuration changes on NetScaler appliances outside of authorised change windows.
- Where SIP ALG is enabled on an LSN group, monitor appliance stability and availability metrics for signs of memory-related instability.
- Where feasible, review firewall/WAF logs for connections to the appliance's authentication or Gateway endpoints from unfamiliar or unexpected source IP ranges.
- Ensure centralised, retained logging (SIEM/log aggregation) is in place for NetScaler appliances to support retrospective investigation.
- Treat any unpatched appliance meeting the CVE-2026-19490 pre-conditions as being under active probing, not just theoretical risk, and prioritise accordingly.
- Continue to monitor Citrix's advisory (CTX696939), the ACSC alert, and reputable threat intelligence sources for updates, as further indicators or confirmed compromise cases may emerge.
MDR customers: Triskele Labs will continue monitoring vendor and threat intelligence channels for any confirmed indication of exploitation of CVE-2026-19489 or CVE-2026-19490 and will update detections accordingly.
Vulnerability Management customers: Environments have been actively scanned for vulnerable versions of NetScaler ADC and NetScaler Gateway affected by CVE-2026-19489 and CVE-2026-19490 since these CVEs were added to Qualys. Any findings will always be communicated through priority channels.
References
- https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html
- https://australiancybersecuritymagazine.com.au/acsc-warns-of-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/
- https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerabilities-in-citrix-netscaler-application-delivery-controller-adc-and-citrix-netscaler-gateway-products
- https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/
- https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html
- https://previdian.com/CVE-2026-19490
- https://nvd.nist.gov/vuln/detail/CVE-2026-19489
- https://nvd.nist.gov/vuln/detail/CVE-2026-19490