Threat Advisory

NetScaler Flaw Lets Attackers Bypass Authentication

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting NetScaler ADC versions. The bypass hits NetScaler configured as a Gateway or AAA virtual server have been identified in NetScaler ADC, which could allow attackers to bypass authentication and cause denial of service. The overall risk/impact is critical, affecting corporate networks that rely on VPN and single sign-on for remote staff. Affected version ranges include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21.

CVE-2026-19490 (CVSS 9.3): CVE-2026-19490 is an authentication bypass using an alternate path. The advisory classifies it under CWE-288. In short, an attacker reaches a protected function through an unexpected route. The flaw scores high across confidentiality, integrity, and availability. It needs no privileges and no user interaction. Only appliances in specific roles are exposed.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting NetScaler ADC versions. The bypass hits NetScaler configured as a Gateway or AAA virtual server have been identified in NetScaler ADC, which could allow attackers to bypass authentication and cause denial of service. The overall risk/impact is critical, affecting corporate networks that rely on VPN and single sign-on for remote staff. Affected version ranges include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21.

CVE-2026-19490 (CVSS 9.3): CVE-2026-19490 is an authentication bypass using an alternate path. The advisory classifies it under CWE-288. In short, an attacker reaches a protected function through an unexpected route. The flaw scores high across confidentiality, integrity, and availability. It needs no privileges and no user interaction. Only appliances in specific roles are exposed.[emaillocker id="1283"]

CVE-2026-19489 (CVSS 8.8): A memory overflow can trigger unpredictable behavior or denial of service, affecting SIP ALG on a Large Scale NAT group.

These vulnerabilities collectively present a significant risk to corporate networks that rely on VPN and single sign-on for remote staff.

RECOMMENDATION:

We recommend you to update NetScaler ADC to the version 14.1-73.32, 13.1-63.21.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu