Vulnerability
Published 2026-08-19
Verified 2026-09-19

NetScaler ADC/Gateway memory overflow (CVE-2026-19489)

Same CTX696939 bulletin: memory overflow that can cause unpredictable behaviour or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group. CVSS v4.0 8.8. Customer-managed NetScaler ADC and Gateway only. No workaround. Same patched builds as CVE-2026-19490: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP. Distinct from the earlier CVE-2026-8452 memory-overflow card.

Product
NetScaler ADC and NetScaler Gateway (customer-managed)
Versions
14.1 before 14.1-73.32; 13.1 before 13.1-63.21; ADC FIPS before 14.1-73.32 FIPS; ADC FIPS/NDcPP before 13.1-37.277. Precondition: SIP ALG on an LSN group
CVSS
(CVSS 4.0, Cloud Software Group)
Exploited in Australia?
unknown
Patch to
14.1-73.32; 13.1-63.21; 14.1-73.32 FIPS; 13.1-37.277 FIPS/NDcPP

Primary: Citrix CTX696939 · Vendor: Cloud Software Group (vendor) · CVE: CVE-2026-19489, CVE-2026-19490, CVE-2026-8452

vulnerabilities network