Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Citrix NetScaler ADC CVE-2023-3519 lets remote attackers bypass authentication
August 19, 2026
Supply Chain Attacks: How US and EU Enterprises Can Reduce Risk
August 19, 2026
CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks
August 19, 2026
Home/CyberSecurity News/Critical Citrix NetScaler ADC CVE-2023-3519 lets remote attackers bypass authentication
CyberSecurity News

Critical Citrix NetScaler ADC CVE-2023-3519 lets remote attackers bypass authentication

Key Takeaways Cloud Software Group has disclosed two critical vulnerabilities impacting NetScaler ADC and NetScaler Gateway. CVE-2026-19490, an authentication bypass with a CVSS v4.0 score of 9.3,...

Emy Elsamnoudy
Emy Elsamnoudy
August 19, 2026 3 Min Read
3 0

Key Takeaways

  • Cloud Software Group has disclosed two critical vulnerabilities impacting NetScaler ADC and NetScaler Gateway.
  • CVE-2026-19490, an authentication bypass with a CVSS v4.0 score of 9.3, poses a severe risk to remote access infrastructure.
  • CVE-2026-19489, a memory overflow leading to denial-of-service, scores 8.8.
  • Patches are available, and immediate upgrades are strongly recommended for all affected deployments.

Critical Flaws Discovered in Citrix NetScaler ADC and Gateway

Cloud Software Group has issued an urgent security advisory, alerting customers to two significant vulnerabilities within its NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) products. These flaws, if exploited, could allow remote attackers to either completely bypass authentication mechanisms or trigger denial-of-service conditions, severely compromising enterprise remote access and network infrastructure.

Table Of Content

  • Key Takeaways
  • Critical Flaws Discovered in Citrix NetScaler ADC and Gateway
  • Authentication Bypass Poses Major Threat (CVE-2026-19490)
  • Memory Overflow Leads to Denial of Service (CVE-2026-19489)
  • Affected Versions and Remediation
  • What You Should Do

Authentication Bypass Poses Major Threat (CVE-2026-19490)

The more critical of the two vulnerabilities, tracked as CVE-2026-19490, has been assigned a CVSS v4.0 base score of 9.3. Categorized under CWE-288, “Authentication Bypass Using an Alternate Path,” this flaw enables attackers to circumvent authentication on NetScaler appliances when configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.

The exploitability of CVE-2026-19490 varies depending on the specific software build. For NetScaler versions 14.1-43.56 and later, as well as 13.1-61.28 and later, the vulnerability is only exploitable if the appliance has a SAML action configured. However, on older builds, any configuration involving a Gateway or AAA vserver is sufficient to expose the flaw, making a broader range of deployments susceptible. Given that these authentication gateways are primary entry points for remote access, successful exploitation could grant unauthorized access to corporate networks without requiring valid credentials.

Memory Overflow Leads to Denial of Service (CVE-2026-19489)

The second vulnerability, CVE-2026-19489, carries a CVSS v4.0 score of 8.8. This flaw stems from a memory overflow issue, classified under CWE-119, “Improper Restriction of Operations within the Bounds of a Memory Buffer.” The vulnerability is triggered when the Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled within a Large Scale NAT (LSN) group configuration. Successful exploitation could lead to unpredictable appliance behavior or a complete denial-of-service outage, disrupting critical network services reliant on NetScaler for traffic management and NAT translation.

Affected Versions and Remediation

These vulnerabilities impact NetScaler ADC and NetScaler Gateway versions 14.1 before build 73.32, and version 13.1 before build 63.21. This also includes the FIPS and NDcPP variants of these releases. Secure Private Access Hybrid deployments utilizing customer-managed NetScaler instances are also exposed and require the same upgrades. Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings.

Administrators can determine their exposure by examining NetScaler configuration files. For CVE-2026-19489, the presence of LSN group entries with SIP ALG settings confirms the precondition. For CVE-2026-19490, checking for SAML action configurations or existing authentication and VPN vserver entries will reveal if the appliance meets the criteria for exploitation.

Cloud Software Group is urging all customers to upgrade immediately. Recommended patched versions include NetScaler ADC and Gateway 14.1-73.32 or later, 13.1-63.21 or later, or their corresponding FIPS and NDcPP builds.

These vulnerabilities were responsibly disclosed by Samarth Vashisht from JPMorgan Chase’s penetration testing team, highlighting the critical role of coordinated vulnerability research in enhancing the security of widely deployed enterprise infrastructure.

What You Should Do

  • Prioritize Patching: Immediately upgrade all affected NetScaler ADC and NetScaler Gateway instances to the latest patched versions (14.1-73.32+, 13.1-63.21+, or corresponding FIPS/NDcPP builds).
  • Review Configurations: Check your NetScaler configurations for SIP ALG within LSN groups (for CVE-2026-19489) and SAML actions or Gateway/AAA vserver entries (for CVE-2026-19490) to understand your specific exposure.
  • Monitor for Exploitation: Be vigilant for any unusual activity, unauthorized access attempts, or service disruptions following public disclosure, as threat actors are likely to scan for vulnerable systems.
  • Isolate and Segment: Ensure critical network segments are adequately isolated, even if an attacker bypasses the gateway, to limit lateral movement.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Supply Chain Attacks: How US and EU Enterprises Can Reduce Risk

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Microsoft ends support for Windows 11 24H2 Home and Pro editions
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us