<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NetScaler ADC (13.1, 14.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/netscaler-adc-13.1-14.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 19 Aug 2026 16:34:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/netscaler-adc-13.1-14.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Citrix NetScaler ADC and Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-08-citrix-netscaler-vulnerabilities/</link><pubDate>Wed, 19 Aug 2026 16:34:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-citrix-netscaler-vulnerabilities/</guid><description>Citrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.</description><content:encoded><![CDATA[<p>On August 19, 2026, Citrix disclosed critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway products. The vulnerabilities include CVE-2026-19490, an authentication bypass vulnerability with a CVSS score of 9.3, and CVE-2026-19489, a memory overflow vulnerability with a CVSS score of 8.8. The authentication bypass (CVE-2026-19490) is triggered through an alternate path within the Gateway or AAA virtual server configuration, potentially allowing unauthenticated access to the appliance. The memory overflow (CVE-2026-19489) occurs when SIP ALG is enabled within a Large Scale NAT (LSN) group, which may result in unpredictable system behavior or Denial of Service (DoS). Organizations running these versions should prioritize patching to the identified secure releases immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-19490 may allow remote unauthenticated attackers to bypass security controls and gain unauthorized access to the NetScaler appliance, potentially compromising internal resources. CVE-2026-19489 risks the availability of network services by causing service crashes or unpredictable behavior. These vulnerabilities affect various versions of NetScaler ADC and Gateway, including FIPS and NDcPP variants, creating significant risk for organizations relying on these appliances for secure remote access and load balancing.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately audit current NetScaler configurations for the presence of LSN group SIP ALG settings or Gateway/AAA virtual server configurations using the diagnostic commands provided in the official advisory.</li>
<li>Update all instances of NetScaler ADC and NetScaler Gateway to the following versions: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 (for FIPS/NDcPP).</li>
<li>Monitor NetScaler appliance logs and system health metrics for unexpected service restarts or unauthorized access patterns following the patch deployment.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>network-infrastructure</category><category>authentication-bypass</category></item></channel></rss>