Number: AL26-019
Date: September 4, 2026
Audience
This Alert is intended for IT professionals and managers.
Purpose
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Details
The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway)Footnote 1.
In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026Footnote 2.
Tracked as CVE-2026-19490Footnote 3, this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288)Footnote 4. The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.
Tracked as CVE-2026-19489Footnote 5, this vulnerability is a Classic Buffer Overflow vulnerability (CWE-120)Footnote 6. This vulnerability may allow memory overflow leading to unpredictable behavior or Denial of Service conditions.
Pre-conditions for these vulnerabilities are that the NetScaler ADC or NetScaler Gateway 14.1-43.56 and later, as well as 13.1-61.28 and later, must be configured as a SAML IdP (Security Assertion Markup Language Identity Provider).
Earlier builds with Gateway or AAA configuration are also vulnerable.
To determine if organizations are impacted, it is recommended to check if the appliance meets the precondition by inspecting the NetScaler configuration for the specified strings:
For CVE-2026-19489:
"add lsn group.*sipalg.*"
For CVE-2026-19490:
SAML action configuration:
"add authentication samlAction.*"
Auth or VPN vserver:
"add authentication vserver .*" or "add vpn vserver .*"
Further information about the impacted configurations can be found in the Citrix advisoryFootnote 1.
Suggested actions
The Cyber Centre recommends that organizations using Citrix NetScaler ADC and NetScaler Gateway appliances (particularly for SAML IDP-configured appliances), review the Citrix security bulletinFootnote 1 and update/upgrade the affected systems to the following vendor-supported fixed versions:
| Affected product | Affected versions | Fixed versions |
|---|---|---|
| NetScaler ADC and NetScaler Gateway 14.1 | versions prior to 14.1-73.32 | version 14.1-73.32 and later |
| NetScaler ADC and NetScaler Gateway 13.1 | versions prior to 13.1-63.21 | version 13.1-63.21 and later |
| NetScaler ADC FIPS | versions prior to 14.1-73.32 FIPS | version 14.1-73.32 FIPS and later |
| NetScaler ADC FIPS and NDcPP | versions prior to 13.1-37.277 | version 13.1-37.277 and later |
The Cyber Centre also recommends organizations to:
- determine the current version of software on each appliance
- identify NetScaler appliances configured as Gateway services or AAA virtual servers
- review configurations for SAML authentication deployments, where applicable
- prioritize patching affected systems on an emergency basis
- monitor authentication logs and network activity for indications of unauthorized access
- follow Citrix incident response guidance if compromise is suspected
- after patching, verify the appliance is running the updated version and review logs for unusual activity
Citrix has provided steps to take if NetScaler ADC or NetScaler Gateway are suspected to be compromisedFootnote 7.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security ActionsFootnote 8 with an emphasis on the following topics:
- consolidate, monitor, and defend Internet gateways
- patch operating systems and applications
- harden operating systems and applications
- isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal, or email contact@cyber.gc.ca.