
Citrix has released patches for two critical vulnerabilities affecting its NetScaler ADC and NetScaler Gateway products. The most severe, CVE-2026-19490, is an authentication bypass flaw with a CVSS score of 9.3 that could allow attackers to bypass login checks under specific configuration conditions. A second vulnerability, CVE-2026-19489, is a memory overflow issue with a CVSS score of 8.8 that can lead to denial of service.

Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges. NetScaler ADC and NetScaler Gatew