
Executive Security Advisory: Citrix NetScaler CVE-2026-19490 – authentication bypass under attack
Executive summary: Citrix NetScaler is a central networking and security platform commonly used as a VPN/remote-access gateway, to provide secure external access to business applications, or to distribute web services. From a management perspective, it may be the login portal employees use to access company applications or virtual workplaces from outside the organisation. If your IT provider operates Citrix NetScaler, NetScaler ADC, or NetScaler Gateway, this alert should be reviewed with them immediately.
Management summary
Citrix disclosed CVE-2026-19490 in NetScaler ADC and NetScaler Gateway. Under specific Gateway or AAA configurations, the flaw can allow authentication bypass without prior credentials. Since September 3, 2026, requests matching a published proof of concept have been observed. This is evidence of exploitation attempts, although it does not by itself prove successful compromise of real-world systems. Internet-facing NetScaler appliances therefore require urgent action.
What is the issue?
CVE-2026-19490 is an Authentication Bypass Using an Alternate Path rated CVSS v4.0 9.3. It affects customer-managed NetScaler ADC and NetScaler Gateway when configured as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) or an AAA virtual server. On newer vulnerable builds, a SAML action is also required; older builds are affected by the Gateway/AAA configuration alone.
Why is it dangerous?
NetScaler Gateway commonly sits directly on the internet and protects access to internal applications and remote-access services. A successful authentication bypass may let an attacker reach protected Gateway or AAA functions without valid authentication. This is not automatically a confirmed remote-code-execution path, but it can provide a highly valuable foothold into the internal environment.
Who is affected?
Affected versions are NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21. For 14.1-FIPS, 14.1-73.32 FIPS or later is fixed; for 13.1-FIPS and 13.1-NDcPP, 13.1-37.277 or later is required. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by the provider.
Recommended actions
Priority 1 – today: inventory every internet-facing NetScaler ADC/Gateway appliance and verify its build plus Gateway/AAA configuration. Priority 1: upgrade immediately to 14.1-73.32+, 13.1-63.21+, 14.1-73.32 FIPS+ or 13.1-37.277+. Citrix lists no effective vendor workaround other than updating. If an update cannot be deployed immediately, remove or tightly restrict public exposure where operationally feasible; this is risk reduction, not a replacement for the patch. Priority 2: review authentication, VPN and AAA logs for unusual successful sessions, new access and suspicious configuration changes, and treat anomalies as a potential security incident.
Our assessment
Priority: HIGH / PATCH NOW for exposed affected systems. The key combination is an unauthenticated remote authentication bypass, a public proof of concept and observed exploitation attempts against an internet-edge product. Sources: Citrix Security Bulletin CTX696939, CERT-EU Security Advisory 2026-010, Canadian Centre for Cyber Security AL26-019 and BleepingComputer, September 4, 2026.





