CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
citrix · netscaler application delivery controller
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

Several organizations, including River Bank & Trust, Indra Group, and Nidec, have recently fallen victim to ransomware attacks. These incidents have led to potential data exfiltration and service disruptions. Additionally, a new AI-driven ransomware technique has been demonstrated that exploits browser APIs to encrypt user files.