NCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconfigureerd als SIP ALG binnen een Large Scale NAT (LSN) groep. Deze fout in de geheugenallocatie kan leiden tot onvoorspelbaar gedrag of een denial of service, waardoor de normale werking van het systeem verstoord kan worden. De kwetsbaarheid met kenmerk CVE-2026-19490 maakt het voor een aanvaller mogelijk om via een alternatieve route de normale authenticatiemechanismen te omzeilen, om zodoende ongeautoriseerde toegang tot het systeem te verkrijgen. Om kwetsbaar te zijn moeten de producten in combinatie met specifieke versies geconfigureerd zijn als Gateway (VPN-virtuele server, ICA Proxy, CVPN, RDP Proxy), AAA virtual server of configureerd zijn als SAML Identity Provider. Dit laatste is geen gebruikelijke configuratie. UPDATE Er is Proof of Concept code beschikbaar voor CVE-2026-19490. Het NCSC acht het zeer waarschijnlijk dat op korte termijn misbruik zal plaatsvinden.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-194890.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-19490Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 88% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19489 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19490 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedCitrix Products Multiple Vulnerabilitieshkcert
- unknownexploitedAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…cccs
- unknownexploitedCitrix security advisory (AV26-833) - Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- critical[UPDATE] [kritisch] Citrix Systems NetScaler (Gateway und ADC): Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0318 [1.00] [M/M] Vulnerabilities resolved in Citrix NetScaler ADC and NetScaler Gatewayncsc-nl
- unknownMultiple vulnerabilities in Citrix products (20 August 2026)cert-fr-avis
- criticalexploited2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gatewaycert-eu
- unknownCVE-2026-19490: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
- unknownCVE-2026-19489: Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 throug…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustratorncsc-nl · 2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Managerncsc-nl · 2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
- unknownNCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktopncsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09