CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5774

As cited

Copy frozen at (site build).

vulnerabilities

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

The Canadian Centre for Cyber Security released an alert on September 4, 2026, warning of two vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. CVE-2026-19490 is an authentication bypass affecting SAML Identity Provider (IdP) configurations that allows unauthenticated remote attackers to circumvent authentication controls, while CVE-2026-19489 is a buffer overflow that can cause memory corruption or denial of service. Affected versions include NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, with patched versions available from the vendor.

Why it matters: Organizations operating NetScaler appliances configured as gateways, authentication servers, or SAML IdP services face immediate risk of unauthorized access or service disruption and should prioritize emergency patching to the fixed versions and review authentication logs for evidence of compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

The Canadian Centre for Cyber Security released an alert on September 4, 2026, warning of two vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. CVE-2026-19490 is an authentication bypass affecting SAML Identity Provider (IdP) configurations that allows unauthenticated remote attackers to circumvent authentication controls, while CVE-2026-19489 is a buffer overflow that can cause memory corruption or denial of service. Affected versions include NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, with patched versions available from the vendor.

Why it matters: Organizations operating NetScaler appliances configured as gateways, authentication servers, or SAML IdP services face immediate risk of unauthorized access or service disruption and should prioritize emergency patching to the fixed versions and review authentication logs for evidence of compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary