Citrix Product Security Update Advisory

Citrix Product Security Update Advisory

Citrix has released security updates to address vulnerabilities in NetScaler ADC and NetScaler Gateway.

  • Affected products include NetScaler ADC and Gateway versions prior to 13.1-63.21 And prior to 14.1-73.32.
  • Additional affected products include NetScaler ADC FIPS versions prior to 13.1-37.277 And prior to 14.1-73.32 FIPS, as well as NetScaler ADC NDcPP versions prior to 13.1-37.277.
  • The vulnerabilities that have been addressed are CVE-2026-19489 and CVE-2026-19490.
  • CVE-2026-19489 is a denial-of-service vulnerability caused by a memory overflow (an error where data is written beyond the memory bounds) in NetScaler ADC and NetScaler Gateway.
  • CVE-2026-19490 is an authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway that exploits an alternative path.
  • Citrix has announced that it has provided Vulnerability Patches for these vulnerabilities through its latest updates.
  • The latest Vulnerability Patches are for NetScaler ADC and Gateway 13.1-63.21 Or later, and 14.1-73.32 Or later.
  • NetScaler ADC FIPS must be version 13.1-37.277 Or higher, or 14.1-73.32 FIPS or higher.
  • NetScaler ADC NDcPP must be version 13.1-37.277 Or higher.
  • Instructions for updating to the latest version, as outlined on the reference site, are included.