New Critical Citrix NetScaler Vulnerabilities Released

Citrix and the Canadian Centre for Cyber Security released an advisory detailing vulnerabilities for versions of Citrix NetScaler ADC and NetScaler Gateway.

These vulnerabilities cover two main areas of concern:

Your organization is vulnerable if you are running affected code or configuration.

This table summarizes affected and fixed code version for each product:

Affected Product Affected Versions Fixed Versions
NetScaler ADC & NetScaler Gateway 14.1 prior to 14.1-73.32 14.1-73.32 and later
NetScaler ADC & NetScaler Gateway 13.1 prior to 13.1-63.21 13.1-63.21 and later
NetScaler ADC FIPS prior to 14.1-73.32 FIPS 14.1-73.32 FIPS and later
NetScaler ADC FIPS and NDcPP prior to 13.1-37.277 13.1-37.277 and later

Your configuration is affected if it contains the following elements:

  • CVE-2026-19489: "add lsn group.*sipalg.*"

  • CVE-2026-19490 (SAML action configuration): "add authentication samlAction.*"

  • Auth or VPN vserver: "add authentication vserver .*" or "add vpn vserver .*"


For more information on security updates, please see Citrix’s advisory page for these vulnerabilities.

Please patch affected systems as soon as possible! Fixed software is available via Citrix. Please also regularly audit your internet gateways, consolidating where possible, isolate web-facing applications, and harden your operating systems and applications, including regular patching.

General guidance for protecting your environment is available from the Canadian Centre for Cyber Security.