2026-08-20HIGHexploitedThe precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver alone is enough
Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8.
cve · CVE-2026-19489
Coverage
1
first 2026-08-20 → last 2026-09-29
Latest activity
2026-09-08
The precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, energy, finance · regions: europe
Sources cited
9
8 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-19489, newest first. Check the date before acting on an older one.
- Inspect every NetScaler running configuration for2026-08-20CVE-2026-19490 +1
add authentication samlAction,add authentication vserveroradd vpn vserver, and patch any appliance that matches to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS or 13.1-37.277 now, on builds older than 14.1-43.56 / 13.1-61.28 and on 13.1 FIPS, a Gateway or AAA virtual server alone is enough to be exposed, with no SAML action required. A public exploit is live and sensor telemetry confirms attempts against it; review authentication and session logs on every appliance that was internet-exposed and unpatched since 2026-09-03 for signs of a successful bypass before treating it as clean.
Defender insights
What each entry about CVE-2026-19489 tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass · ATT&CK page ↗
Entries about Citrix NetScaler ADC/Gateway, memory overflow leading to unpredictable behaviour or denial of service; requires SIP ALG enabled on a Large Scale NAT group. CVSS 8.8. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Citrix NetScaler×1
- Citrix NetScaler ADC/Gateway, authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19.×1
Where this entity is cited
Source distribution
- api.first.org2 (22%)
- advisories.ncsc.nl1 (11%)
- bleepingcomputer.com1 (11%)
- cert.europa.eu1 (11%)
- cisa.gov1 (11%)
- fieldeffect.com1 (11%)
- previdian.com1 (11%)
- rapid7.com1 (11%)
External references
All cited sources (9)
- cert.europa.euprimaryCERT-EUhttps://cert.europa.eu/publications/security-advisories/2026-010/
- advisories.ncsc.nlNCSC-NL (Nationaal Cyber Security Centrum)https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318
- api.first.orgFIRST.org (EPSS)https://api.first.org/data/v1/epss?cve=CVE-2026-19489
- api.first.orgFIRST.org (EPSS)https://api.first.org/data/v1/epss?cve=CVE-2026-19490
- bleepingcomputer.comBleepingComputer, citing Previdian (Ryan Dewhurst)https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/
- cisa.govCISA Known Exploited Vulnerabilities Catalog (JSON feed)https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- fieldeffect.comField Effect Security Intelligence Teamhttps://fieldeffect.com/blog/early-exploitation-citrix-netscaler-vulnerability
- previdian.comPrevidian (Ryan Dewhurst)https://previdian.com/CVE-2026-19490
- rapid7.comRapid7https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/