What has changed

Citrix published fixes on 19 August for two vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. CVE-2026-19490 is an authentication bypass using an alternate path, rated 9.3 under CVSS 4.0. CVE-2026-19489 is a memory-overflow weakness that can cause unpredictable behaviour or denial of service, rated 8.8. CERT-EU has also reviewed the bulletin and recommends updating affected devices as soon as possible.

The sources do not report exploitation. That distinction matters: the high technical ratings and the position of a gateway justify prompt action, but they do not prove that an organisation has been attacked or compromised. Teams should base incident decisions on their own exposure and evidence rather than turning severity into an unsupported breach claim.

[1][2]

Which appliances are affected

Citrix lists NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21. NetScaler ADC 14.1 FIPS before 14.1-73.32 FIPS is affected, as are 13.1 FIPS and NDcPP builds before 13.1-37.277. Secure Private Access Hybrid deployments using NetScaler instances are included. The bulletin applies to customer-managed appliances; Citrix says it has updated its managed cloud services and managed Adaptive Authentication.

Configuration determines whether each flaw applies. The memory-overflow issue requires SIP ALG to be enabled on a Large Scale NAT group. The authentication bypass concerns appliances configured as a Gateway or AAA virtual server, with SAML requirements varying by release. An inventory entry saying only ‘NetScaler 14.1’ is therefore insufficient: defenders need the complete build, management model and relevant configuration.

[1][2]

What defenders should do

Identify every production, disaster-recovery and standby NetScaler instance, including those operated by a supplier. Record the full running build and whether it provides SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA services. Check for the SAML action and SIP ALG on Large Scale NAT configurations described in Citrix's bulletin. Use the vendor's supported inspection method and have an authorised administrator review the result; do not infer exposure from an external scan alone.

Install 14.1-73.32 or later, 13.1-63.21 or later, 14.1-73.32 FIPS or later, or 13.1-37.277 FIPS/NDcPP or later as appropriate. Citrix lists no workaround or mitigating factor, so network restrictions should not be presented as a replacement for the fixed build. Follow the supported update process, preserve the current configuration, plan rollback, and test authentication, application delivery, monitoring and high availability afterwards.

Where an affected gateway was internet-facing, retain relevant gateway, identity-provider and administrative logs according to the organisation's evidence policy. Review them proportionately for unexpected authentication or configuration activity. Neither cited source provides a compromise indicator or says the flaws are exploited, so absence of a particular indicator cannot prove safety, and ordinary anomalies should not be labelled exploitation without supporting evidence.

  • Locate customer-managed, supplier-run and standby NetScaler instances.
  • Capture the complete build and the relevant Gateway, AAA, SAML and SIP ALG configuration.
  • Move affected appliances to the appropriate fixed release or later supported build.
  • Test access, application delivery, monitoring and resilience after updating.
  • Keep useful logs and escalate only evidence-backed signs of suspicious activity.
[1][2]

The Beekeeper view

An edge appliance is easy to recognise as important but surprisingly easy to record badly. Product name and major version do not settle this advisory; exposure turns on the exact build, service role and configuration. That makes asset detail and operational ownership part of the security control, not administrative garnish.

The immediate task is a controlled update. The durable improvement is to keep gateways in a register that links each running build to an owner, supplier, configuration role, maintenance route and evidence source. When the next bulletin arrives, that turns uncertainty into a short, auditable decision rather than several hours of infrastructure archaeology.

[1][2]
Confirm both the full build and the relevant gateway, AAA, SAML or SIP ALG configuration, then install the supported fixed release: Citrix says there is no workaround.

Primary sources

  1. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 — Citrix, 19 August 2026
  2. Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway — CERT-EU, 19 August 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.