Buffer overflow in Citrix Netscaler ADC and Citrix NetScaler Gateway - CVE-2026-19489
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of operations within the bounds of a memory buffer in the SIP ALG processing component when handling SIP ALG traffic on a Large Scale NAT group configuration. A remote attacker can send crafted network traffic to cause a denial of service.
Only appliances with SIP ALG enabled on a Large Scale NAT group configuration are vulnerable.
Affected software
Citrix NetScaler Gateway
How to mitigate CVE-2026-19489
Citrix NetScaler Gateway - addressed in versions 13.1-63.21, 14.1-73.32