Citrix disclosed CVE-2026-19490 and CVE-2026-19489 on August 20, two more flaws in NetScaler ADC and Gateway, the appliance many hospitals put in front of their VPN and federated login. CVE-2026-19490 is an authentication bypass using an alternative path, scored 9.3 under CVSS version 4.0, and it reaches any appliance configured as a gateway, meaning an SSL VPN, ICA Proxy, CVPN, or RDP Proxy virtual server, or as an AAA virtual server. CVE-2026-19489 is a memory overflow in the SIP ALG feature when an LSN group is configured, scored 8.8, and it can crash the appliance outright.
The exposed builds are NetScaler ADC and Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus the FIPS and NDcPP variants before their matching point releases. Citrix shipped the fix the same day it disclosed both bugs. CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on September 9 and gave federal civilian agencies until September 12 to remediate it, a three day window that says more about CISA's patience with this appliance family than it does about the bug itself.
Philips published its own advisory on September 29, more than five weeks after Citrix's disclosure, and said no Philips products are known to be impacted. That is the latest in a run of NetScaler advisories Philips has issued this year, each clearing its own name against a different CVE pair. The appliance itself carries no Philips code, but it often sits in front of Philips systems anyway, carrying remote service sessions and cloud control planes back into hospital networks.
An authentication bypass using an alternative path means the gateway's login decision gets routed around rather than forced open. That is worse than a brute-force risk in one specific way: the attacker never supplies a credential that would show up in a failed login log. Rapid7 had not observed active exploitation as of August 19, but it watched how fast the two prior NetScaler bugs this year went from proof of concept to attack and recommended emergency patching rather than waiting for one.
For device manufacturers the pattern matters more than any single CVE. NetScaler, a SAML library, Next.js, an enterprise PLM platform. None of it is code a manufacturer wrote, yet all of it sits somewhere in the path between a device and the hospital network that depends on it. Philips has made a habit of saying, in public and inside weeks, whether that path held. A manufacturer that stays quiet on its own perimeter exposure leaves the customer guessing at the one moment guessing costs the most.