Critical CVE-2026-19490 Authentication Bypass Vulnerability Discovered in Citrix NetScaler ADC and Gateway

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Critical Authentication Bypass Vulnerability in Citrix NetScaler ADC and Gateway

On August 19, 2026, a significant security advisory was issued regarding CVE-2026-19490, an authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. This vulnerability has been assigned a CVSS v4.0 base score of 9.3, indicating its critical nature. It can be exploited remotely by unauthenticated attackers without requiring user interaction or elevated privileges.

Citrix NetScaler ADC and Gateway are widely utilized enterprise networking solutions, often positioned at the network perimeter. The ADC provides essential services such as application delivery, traffic management, load balancing, and SSL/TLS offloading, while the Gateway facilitates secure remote access and VPN capabilities. Due to their common deployment in enterprise DMZs and exposure to the public internet, these systems are attractive targets for threat actors, making vulnerabilities like CVE-2026-19490 particularly concerning.

The vulnerability affects the following versions of Citrix products:

  • NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-63.21
  • NetScaler ADC FIPS: Versions prior to 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP: Versions prior to 13.1-37.277

As of the advisory date, Rapid7 has not detected any active exploitation of CVE-2026-19490 in the wild. However, organizations are strongly advised to prioritize patching affected systems immediately, as Citrix products are often targeted and can quickly become compromised.

Mitigation Guidance

Organizations utilizing affected NetScaler ADC or NetScaler Gateway appliances should consult the official Citrix advisory and apply the necessary updates without delay. The fixed versions for the affected products are as follows:

  • NetScaler ADC and NetScaler Gateway: 14.1-73.32 and later
  • NetScaler ADC and NetScaler Gateway: 13.1-63.21 and later for 13.1
  • NetScaler ADC 14.1-FIPS: 14.1-73.32 FIPS and later
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.277 and later

To determine if systems are vulnerable to CVE-2026-19490, Citrix recommends inspecting the NetScaler configuration for specific entries. If any of these entries are present and the systems are running affected versions, they may be exploitable.

For further details and the latest guidance, refer to the official Citrix advisory.

Customers of Rapid7 can assess their exposure to CVE-2026-19490 using a vulnerability check that is expected to be available in the content release on August 20.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Attacker Compromises AI Coding Assistant, Spreads Shai-Hulud Worm to 100 Repositories

Mandiant has reported that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, subsequently spreading the Shai-Hulud worm across approximately...

Norwegian Authorities Investigate Telenor for Alleged Complicity in Myanmar Junta’s Crimes Against Humanity

Law enforcement agencies in Norway are investigating telecommunications giant Telenor for potential complicity in crimes against humanity linked to its operations with Myanmar's military...

Ransomware Incidents Surge in the Gulf, Targeting Businesses Amid Increased Cyber Threats

Ransomware incidents in the Gulf region have surged dramatically, with organized criminal groups increasingly targeting businesses in sectors where disruption can compel victims to...

Palo Alto Networks Develops Behavioral Clustering Model for Cloud Identity Security

Mapping Cloud Identities: A New Approach to Security As organizations increasingly migrate to cloud environments, the complexity of managing identities—human, machine, and autonomous agents—has become...