AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Number: AL26-019 Date: September 4, 2026 Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) Footnote 1 . In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026 Footnote 2 . Tracked as CVE-2026-19490 Footnote 3 , this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288) Footnote 4 . The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Tracked as CVE-2026-19489 Footnote 5 , this vulnerability is a Classic Buffer Overflow vulnerability (CWE-120) Footnote 6 . This vulnerability may allow memory overflow leading to unpredictable behavior or Denial of Service conditions. Pre-conditions for these vulnerabilities are that the NetScaler ADC or NetScaler Gateway 14.1-43.56 and later, as well as 13.1-61.28 and later, must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider). Earlier builds with Gateway or AAA configuration are also vulnerable. To determine if organizations are impacted, it is recommended to check if the appliance meets the precondition by inspecting the NetScaler configuration for the specified strings: For CVE-2026-19489: " add lsn group.*sipalg.* " For CVE-2026-19490: SAML action configuration: " add authentication sa
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-19490Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 88% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-194890.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19490 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19489 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCitrix Products Multiple Vulnerabilitieshkcert
- unknownexploitedCitrix security advisory (AV26-833) - Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gatewayncsc-nl
- critical[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl
- unknownMultiple vulnerabilities in Citrix products (20 August 2026)cert-fr-avis
- criticalexploited2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu
- unknownCVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
- unknownCVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09
- criticalFortinet security advisory (AV26-023) - Update 12026-09-09