Citrix found two more holes in NetScaler — one skips the login screen completely

Three weeks after the last NetScaler patch-now story, Citrix is back with a critical bug that needs no password and no user interaction at all.

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-19490 (CVSS 9.3) is an authentication bypass on NetScaler ADC/Gateway when configured as an AAA virtual server or Gateway with SAML Action — no credentials needed.

The short version

CVE-2026-19489 (CVSS 8.8) is a separate memory-overflow DoS bug that only applies with SIP ALG enabled on a Large Scale NAT setup.

The short version

Fixed builds: NetScaler ADC/Gateway 14.1-73.32+ and 13.1-63.21+, plus matching FIPS/NDcPP builds.

The short version

As of August 19, Citrix and Rapid7 had not observed active exploitation — but NetScaler bugs have a well-documented history of getting weaponized within days of disclosure.

The short version

This is a different vulnerability pair from the CVE-2026-8452 SAML heap overflow covered three weeks earlier — patching one does not patch the other.

The mitigation Citrix actually offers

If you run NetScaler Console, Global Deny Lists on firmware 14.1-60.52+ or 13.1-63.16+ can block the attack path without a full upgrade. It's a stopgap, not a fix — schedule the real upgrade…

Aliteq

Read the full story

Citrix found two more holes in NetScaler — one skips the login screen completely

Read the full story on Aliteq