Multiple security vulnerabilities affecting NetScaler ADC versions. The bypass hits NetScaler configured as a Gateway or AAA virtual server have been identified in NetScaler ADC, which could allow attackers to bypass authentication and cause denial of service. The overall risk/impact is critical, affecting corporate networks that rely on VPN and single sign-on for remote staff. Affected version ranges include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21.
CVE-2026-19490 (CVSS 9.3): CVE-2026-19490 is an authentication bypass using an alternate path. The advisory classifies it under CWE-288. In short, an attacker reaches a protected function through an unexpected route. The flaw scores high across confidentiality, integrity, and availability. It needs no privileges and no user interaction. Only appliances in specific roles are exposed.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting NetScaler ADC versions. The bypass hits NetScaler configured as a Gateway or AAA virtual server have been identified in NetScaler ADC, which could allow attackers to bypass authentication and cause denial of service. The overall risk/impact is critical, affecting corporate networks that rely on VPN and single sign-on for remote staff. Affected version ranges include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21.
CVE-2026-19490 (CVSS 9.3): CVE-2026-19490 is an authentication bypass using an alternate path. The advisory classifies it under CWE-288. In short, an attacker reaches a protected function through an unexpected route. The flaw scores high across confidentiality, integrity, and availability. It needs no privileges and no user interaction. Only appliances in specific roles are exposed.[emaillocker id="1283"]
CVE-2026-19489 (CVSS 8.8): A memory overflow can trigger unpredictable behavior or denial of service, affecting SIP ALG on a Large Scale NAT group.
These vulnerabilities collectively present a significant risk to corporate networks that rely on VPN and single sign-on for remote staff.
We recommend you to update NetScaler ADC to the version 14.1-73.32, 13.1-63.21.
The following reports contain further technical details:
[/emaillocker]