CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8.

cve · CVE-2026-19489

Coverage
1
first 2026-08-20 → last 2026-09-29
Latest activity
2026-09-08
The precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, energy, finance · regions: europe
Sources cited
9
8 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-19489, newest first. Check the date before acting on an older one.

  • Inspect every NetScaler running configuration for add authentication samlAction, add authentication vserver or add vpn vserver, and patch any appliance that matches to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS or 13.1-37.277 now, on builds older than 14.1-43.56 / 13.1-61.28 and on 13.1 FIPS, a Gateway or AAA virtual server alone is enough to be exposed, with no SAML action required. A public exploit is live and sensor telemetry confirms attempts against it; review authentication and session logs on every appliance that was internet-exposed and unpatched since 2026-09-03 for signs of a successful bypass before treating it as clean.
    2026-08-20CVE-2026-19490 +1

Defender insights

What each entry about CVE-2026-19489 tells a defender to do, newest first.

2026-08-20HIGHexploitedThe precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver alone is enough

Story timeline

  1. 2026-08-20CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed
    trending-vulnerabilitiesThe precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver alone is enough
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass · ATT&CK page ↗

Entries about Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8. (1)

2026-08-20 · view entry permalink →

HIGHCVE-2026-19490 +1exploitedupdatedNATOA1

CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed

Citrix published a security bulletin on 2026-08-19 covering two vulnerabilities in NetScaler ADC and NetScaler Gateway, and CERT-EU issued its own advisory for its constituency the same day, recommending that affected devices be updated as soon as possible (CERT-EU, 2026-08-19). The more serious of the two, CVE-2026-19490, is described as an authentication bypass using an alternate path and scored 9.3 (CERT-EU, 2026-08-19), a CVSS v4.0 base score, per Rapid7's analysis of the same advisory (Rapid7, 2026-08-19). It applies where the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server, which is the configuration that fronts remote access and authentication brokering for the network behind it.

The part that decides how much of an estate is exposed is version-dependent, and it cuts the wrong way for anyone behind on builds: on 14.1-43.56 or later and 13.1-61.28 or later the flaw applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS, a Gateway or AAA virtual server configuration is sufficient on its own (CERT-EU, 2026-08-19). An operator who checks only for SAML and concludes they are unaffected will be wrong on exactly the appliances that are furthest behind. The second flaw, CVE-2026-19489, is a memory overflow that can lead to unpredictable behaviour or denial of service, and it is reachable only where SIP ALG is enabled inside a Large Scale NAT group configuration (CERT-EU, 2026-08-19).

Detection here is thin by nature; an authentication bypass on an appliance leaves no failed-credential trail, because the point of it is that the credential step does not happen. The telemetry class that carries signal is the authentication and session record on the Gateway or AAA virtual server itself: a session established for a user identity with no preceding credential-validation or SAML assertion-processing event for that same session, and session establishment from addresses or client profiles that do not match the population that normally reaches the appliance. Because CVE-2026-19489 manifests as unpredictable behaviour or a service failure rather than as a login, an unexplained NetScaler restart or packet-engine fault on an appliance carrying an LSN group with SIP ALG belongs in the same review rather than in capacity triage. Fixed builds are 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 (Rapid7, 2026-08-19); where CVE-2026-19489 cannot be patched immediately, SIP ALG on LSN groups that do not need it is a configuration that can simply be turned off.

The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path.

CERT-EU 2026-08-19

As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.

Rapid7 2026-08-19

PoC code is available for CVE-2026-19490. NCSC considers it highly likely that abuse will occur in the short term. (translated from Dutch)

NCSC-NL (Nationaal Cyber Security Centrum) 2026-09-07

On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany.

BleepingComputer, citing Previdian (Ryan Dewhurst) 2026-09-04
Updaterun 2026-09-08T0411Z-intelupdated_atcvestagsactionssourcesevidenceclassificationsourcing_notebody

A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03 (NCSC-NL, 2026-09-07). Vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching that PoC from three distinct source IPs, geolocated to Australia, the United States and Germany, on 2026-09-03 (BleepingComputer, citing Previdian, 2026-09-04), and Previdian's own tracker, refreshed 2026-09-08, now records 18 exploitation attempts total from 9 unique attacker IPs across 5 countries (Australia, Germany, Japan, Taiwan and the United States) (up from the three-IP, three-country snapshot reported four days earlier) with sensor activity most recently observed 2026-09-07: evidence of exploitation attempts, though not confirmation of successful compromise (Previdian, 2026-09-08). Field Effect separately reported on the same activity and adds an operationally important precondition detail: on some newer builds the bypass additionally requires a configured SAML authentication action, while on older affected versions a Gateway or AAA virtual server configuration alone is enough, consistent with, and sharpening, this entry's own version-dependent exposure boundary above (Field Effect Security Intelligence Team, 2026-09-04). NCSC-NL updated its advisory on 2026-09-07 specifically to flag that PoC code is now public and that it assesses imminent widespread exploitation as highly likely (translated from Dutch) (NCSC-NL, 2026-09-07). CVE-2026-19490 had not been added to CISA's KEV catalog as of this update (see the correction below).

Correctionrun 2026-09-10T0410Z-intelcvestagsbodysources

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a remediation due date of 2026-09-12 for federal civilian agencies. This CVE was already recorded here as exploited before this listing, so the addition is a jurisdiction-agnostic confirmation of what this entry already stated rather than a new exploitation-status development.

Correctionrun 2026-09-29T2134Z-auditevidencesummary

The summary of this entry still said Rapid7 had observed no exploitation, the state on 2026-08-19. As the updates of 2026-09-08 and 2026-09-10 record, a public proof of concept appeared around 2026-09-03, exploitation attempts followed the same day, and CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09. The summary now reflects that.

Builds on: CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed…

vulnerability20 Aug 04:33Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • api.first.org2 (22%)
  • advisories.ncsc.nl1 (11%)
  • bleepingcomputer.com1 (11%)
  • cert.europa.eu1 (11%)
  • cisa.gov1 (11%)
  • fieldeffect.com1 (11%)
  • previdian.com1 (11%)
  • rapid7.com1 (11%)