Citrix Product Security Update Advisory
Citrix has released security updates to address vulnerabilities in NetScaler ADC and NetScaler Gateway.
- Affected products include NetScaler ADC and Gateway versions prior to 13.1-63.21 And prior to 14.1-73.32.
- Additional affected products include NetScaler ADC FIPS versions prior to 13.1-37.277 And prior to 14.1-73.32 FIPS, as well as NetScaler ADC NDcPP versions prior to 13.1-37.277.
- The vulnerabilities that have been addressed are CVE-2026-19489 and CVE-2026-19490.
- CVE-2026-19489 is a denial-of-service vulnerability caused by a memory overflow (an error where data is written beyond the memory bounds) in NetScaler ADC and NetScaler Gateway.
- CVE-2026-19490 is an authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway that exploits an alternative path.
- Citrix has announced that it has provided Vulnerability Patches for these vulnerabilities through its latest updates.
- The latest Vulnerability Patches are for NetScaler ADC and Gateway 13.1-63.21 Or later, and 14.1-73.32 Or later.
- NetScaler ADC FIPS must be version 13.1-37.277 Or higher, or 14.1-73.32 FIPS or higher.
- NetScaler ADC NDcPP must be version 13.1-37.277 Or higher.
- Instructions for updating to the latest version, as outlined on the reference site, are included.