{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/netscaler-adc-13.1-14.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-19490"},{"id":"CVE-2026-19489"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NetScaler ADC (13.1, 14.1)","NetScaler Gateway (13.1, 14.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","network-infrastructure","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["Citrix"],"content_html":"\u003cp\u003eOn August 19, 2026, Citrix disclosed critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway products. The vulnerabilities include CVE-2026-19490, an authentication bypass vulnerability with a CVSS score of 9.3, and CVE-2026-19489, a memory overflow vulnerability with a CVSS score of 8.8. The authentication bypass (CVE-2026-19490) is triggered through an alternate path within the Gateway or AAA virtual server configuration, potentially allowing unauthenticated access to the appliance. The memory overflow (CVE-2026-19489) occurs when SIP ALG is enabled within a Large Scale NAT (LSN) group, which may result in unpredictable system behavior or Denial of Service (DoS). Organizations running these versions should prioritize patching to the identified secure releases immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-19490 may allow remote unauthenticated attackers to bypass security controls and gain unauthorized access to the NetScaler appliance, potentially compromising internal resources. CVE-2026-19489 risks the availability of network services by causing service crashes or unpredictable behavior. These vulnerabilities affect various versions of NetScaler ADC and Gateway, including FIPS and NDcPP variants, creating significant risk for organizations relying on these appliances for secure remote access and load balancing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit current NetScaler configurations for the presence of LSN group SIP ALG settings or Gateway/AAA virtual server configurations using the diagnostic commands provided in the official advisory.\u003c/li\u003e\n\u003cli\u003eUpdate all instances of NetScaler ADC and NetScaler Gateway to the following versions: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 (for FIPS/NDcPP).\u003c/li\u003e\n\u003cli\u003eMonitor NetScaler appliance logs and system health metrics for unexpected service restarts or unauthorized access patterns following the patch deployment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T16:34:49Z","date_published":"2026-08-19T16:34:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-citrix-netscaler-vulnerabilities/","summary":"Citrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.","title":"Critical Vulnerabilities in Citrix NetScaler ADC and Gateway","url":"https://feed.craftedsignal.io/briefs/2026-08-citrix-netscaler-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - NetScaler ADC (13.1, 14.1)","version":"https://jsonfeed.org/version/1.1"}