A NetScaler vulnerability could let remote attackers bypass authentication on exposed enterprise gateways without valid credentials.
Successful exploitation could provide unauthorized access to internal corporate resources.
Separately, a second NetScaler vulnerability could trigger denial-of-service conditions on affected appliances.
Key takeaways
- CVE-2026-19490 is a critical NetScaler authentication bypass with a CVSS score of 9.3 that could allow remote attackers to access protected resources without valid credentials.
- CVE-2026-19489 is a high-severity memory overflow flaw that could trigger denial-of-service conditions and disrupt network services.
- NetScaler ADC and Gateway 14.1 and 13.1 are affected, with exploitation requirements varying by software build and configuration.
- Customer-managed NetScaler deployments require action, while Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings.
How the NetScaler vulnerabilities work
Cloud Software Group disclosed two vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
CVE-2026-19490 is a critical authentication bypass flaw, while CVE-2026-19489 is a high-severity memory overflow vulnerability that can cause denial-of-service (DoS) conditions.
Both flaws affect network-facing infrastructure, but their exploitation requirements and potential impact differ.
The vulnerabilities affect NetScaler ADC and NetScaler Gateway 14.1 before build 73.32 and 13.1 before build 63.21, including the corresponding FIPS and NDcPP variants.
Secure Private Access Hybrid deployments that use customer-managed NetScaler appliances are also affected.
Cloud Software Group has already patched its cloud-managed services and Adaptive Authentication offerings.
CVE-2026-19490 could bypass NetScaler authentication
The more severe flaw, CVE-2026-19490, carries a CVSS score of 9.3 and stems from an authentication bypass through an alternate path.
This flaw could allow a remote attacker to circumvent authentication controls on vulnerable NetScaler appliances without valid credentials.
CVE-2026-19490 affects appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, as well as authentication, authorization, and auditing (AAA) virtual servers.
Because these services can act as access points between remote users and internal applications, bypassing authentication could give an attacker unauthorized access to resources that would normally sit behind a trusted security boundary.
CVE-2026-19490 exploitation requirements
The conditions required for exploitation depend on the NetScaler build.
On NetScaler 14.1-43.56 and later and 13.1-61.28 and later, a SAML action must be configured for the vulnerability to be exploitable.
Earlier builds have a broader attack surface because the presence of any Gateway or AAA virtual server configuration is sufficient to meet the vulnerability’s prerequisite conditions.
Administrators should evaluate both the installed NetScaler version and its authentication configuration rather than relying on version information alone to determine whether an appliance meets the conditions for exploitation.
CVE-2026-19489 could cause denial-of-service conditions
The second vulnerability, CVE-2026-19489, carries a CVSS score of 8.8 and stems from improper memory buffer restrictions that can lead to a memory overflow.
Unlike CVE-2026-19490, this flaw does not bypass authentication; instead, it can affect the availability and stability of vulnerable appliances.
Exploitation requires Session Initiation Protocol Application Layer Gateway (SIP ALG) to be enabled within a Large Scale NAT (LSN) group configuration.
Under those conditions, the memory overflow vulnerability could cause unexpected appliance behavior or trigger a DoS condition.
CVE-2026-19489 could disrupt network services
The operational impact could extend beyond the NetScaler appliance itself.
Organizations that depend on affected systems for traffic management, NAT translation, remote connectivity, or other network services could experience service disruptions if an appliance becomes unavailable.
How to mitigate the NetScaler vulnerabilities
Because the vulnerabilities affect both authentication and service availability, security teams should address the immediate flaws while strengthening controls around access, segmentation, and monitoring.
- Patch affected NetScaler ADC and Gateway appliances and review configurations to determine whether systems are impacted by CVE-2026-19490 or CVE-2026-19489.
- Reduce unnecessary external exposure and restrict management interfaces and remote access to trusted networks and approved users.
- Enforce MFA and default-deny access policies to strengthen authentication and limit access to only required resources.
- Segment NetScaler appliances from sensitive internal systems to limit lateral movement and reduce the blast radius of a gateway compromise.
- Monitor and preserve authentication, appliance, firewall, and network logs for unusual access attempts, configuration changes, or service instability.
- Test incident response plans and use attack simulation tools with scenarios around NetScaler compromise.
Together, these measures can reduce exposure to NetScaler-based attacks while building resilience against future gateway and remote access threats.
Bottom line
These vulnerabilities highlight the risk of treating remote access infrastructure as an inherently trusted security boundary.
Security teams should assess which applications, identities, privileged systems, and network segments are reachable through NetScaler and verify that downstream controls can prevent unauthorized access from progressing deeper into the environment.
This analysis can identify paths where a gateway compromise could enable lateral movement or privilege escalation and help determine where stronger segmentation, access controls, and continuous authentication are needed to contain an attack.





