Vulnerability
Published 2026-08-19
Verified 2026-09-19
NetScaler ADC/Gateway memory overflow (CVE-2026-19489)
Same CTX696939 bulletin: memory overflow that can cause unpredictable behaviour or denial of service when SIP ALG is enabled on a Large Scale NAT (LSN) group. CVSS v4.0 8.8. Customer-managed NetScaler ADC and Gateway only. No workaround. Same patched builds as CVE-2026-19490: 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP. Distinct from the earlier CVE-2026-8452 memory-overflow card.
- Product
- NetScaler ADC and NetScaler Gateway (customer-managed)
- Versions
- 14.1 before 14.1-73.32; 13.1 before 13.1-63.21; ADC FIPS before 14.1-73.32 FIPS; ADC FIPS/NDcPP before 13.1-37.277. Precondition: SIP ALG on an LSN group
- CVSS
- (CVSS 4.0, Cloud Software Group)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:L - Exploited in Australia?
- unknown
- Patch to
- 14.1-73.32; 13.1-63.21; 14.1-73.32 FIPS; 13.1-37.277 FIPS/NDcPP
Primary: Citrix CTX696939 · Vendor: Cloud Software Group (vendor) · CVE: CVE-2026-19489, CVE-2026-19490, CVE-2026-8452
