type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, memory-overflow, citrix, netscaler, sip-alg] ยท confidence: high ยท severity: high ยท affected_sectors: [technology] ยท au_impact: false
CVE-2026-19489 โ Citrix NetScaler Memory Overflow
CVE-2026-19489 is a memory-overflow vulnerability in customer-managed Citrix NetScaler ADC and NetScaler Gateway (CVSS 8.8), applicable only when SIP ALG is enabled on Large Scale NAT groups.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-19489 |
| CVSS | 8.8 (High) |
| Product | Citrix NetScaler ADC / NetScaler Gateway (customer-managed) |
| Type | Memory overflow |
| Condition | Applies only when SIP ALG is enabled on Large Scale NAT groups |
| Fixed builds | 14.1-73.32, 13.1-63.21 and equivalents |
| Exploitation | None disclosed in the reporting window |
Impact
The flaw is narrower than the companion authentication bypass (CVE-2026-19490), but deployments running SIP ALG on Large Scale NAT groups are still at risk. Affected customers should move to the fixed builds listed in the Citrix advisory.