Citrix NetScaler ADC and NetScaler Gateway appliances are facing active exploitation of a critical authentication bypass vulnerability tracked as CVE-2026-19490, with attack attempts observed against internet-exposed systems since at least September 3, 2026[9][10][12]. The flaw carries a CVSS v4.0 base score of 9.3 and allows a remote, unauthenticated attacker to circumvent authentication controls on affected gateways without user interaction[1][2][6][10].
The vulnerability is classified as an โAuthentication Bypass Using an Alternate Pathโ issue (CWE-288) that impacts NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server[7][9][10][12]. In this configuration, crafted network requests can be used to bypass normal login flows and gain access to protected functionality on the appliance, including services that organizations rely on for remote access into internal networks[1][4][7]. On newer builds, exploitation typically requires that a SAML action be configured or the appliance be acting as a SAML Identity Provider, whereas older builds present a broader attack surface when operating as a Gateway or AAA virtual server[1][7][14].
CVE-2026-19490 affects NetScaler ADC and Gateway versions 14.1 through 73.32 and 13.1 through 63.21, with fixes delivered in builds 14.1-73.32 and 13.1-63.21 and their corresponding FIPS and NDcPP releases[3][5][14]. The broad version range and critical CVSS score have led multiple vendors and researchers to flag the issue as a high-risk exposure for organizations running NetScaler as their primary remote access gateway[1][6][13]. One independent analysis estimated more than 22,000 NetScaler SSL VPN and application delivery appliances exposed to the internet and susceptible to CVE-2026-19490 prior to patching[9]. The CVE was published on August 19, 2026, initially with no evidence of exploitation and a relatively low predicted exploitation probability, underscoring how quickly the risk profile has shifted[2][11][15].
Attack activity appears to have accelerated following the public release of a proof-of-concept exploit, with threat actors reportedly targeting CVE-2026-19490 in the days after a credible PoC was posted on GitHub[10][12]. Security researchers have since observed scanning and exploitation attempts against vulnerable NetScaler gateways, confirming that opportunistic attackers are actively probing for unpatched appliances on the public internet[9][10][12]. While no specific threat actor or campaign has been definitively attributed so far, the pattern mirrors prior exploitation of VPN and application delivery controllers, where mass scanning for known bugs quickly precedes targeted intrusions.
For defenders, the most immediate risk is unauthorized access to remote access infrastructure, which can enable credential theft, session hijacking, and lateral movement into internal networks without triggering normal authentication controls. Even in the absence of explicit remote code execution, reliable authentication bypass against a widely deployed VPN gateway is sufficient to enable serious compromise of enterprise environments. Organizations that consume NetScaler for employee remote access or customer-facing applications should assume that exposed, unpatched instances are high-value targets.
Citrix has provided guidance and tooling to help customers identify and remediate vulnerable NetScaler instances, recommending a straightforward upgrade to fixed builds as the primary mitigation for CVE-2026-19490[8][14]. Security advisories and partner analyses explain that customers should inspect their configurations for affected Gateway or AAA virtual server entries, including Auth or VPN vservers, and then upgrade any systems running vulnerable firmware versions[2][7][8]. In addition to patching, organizations are urged to restrict public exposure of NetScaler management interfaces, enable multifactor authentication for remote access, and monitor logs for anomalous VPN sessions or authentication events that could indicate successful abuse of the flaw.
References
- CVE-2026-19490: Critical Citrix NetScaler Flaw – SOC Prime
- CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler …
- CVE-2026-19490 | Tenableยฎ
- CVE-2026-19490: NetScaler ADC Auth Bypass Vulnerability
- CVE-2026-19490 Detail – NVD
- CVE-2026-19490: ADC Vulnerability (CVSS 9.3) – Strix
- AL26-019 – Vulnerabilities impacting Citrix NetScaler ADC …
- Identify and remediate vulnerabilities for CVE-2026-19490
- CVE-2026-19490 Citrix NetScaler Auth Bypass: Patch Now
- CVE-2026-19490 – Exploits & Severity – Feedly
- CVE-2026-19490
- Critical Citrix NetScaler auth bypass now leveraged in attacks
- CVE-2026-19490 (CRITICAL) โ details, PoC & remediation | dbcve.org
- CVE-2026-19490: NetScaler ADC and … – with Identity
- CVE-2026-19490 – Vulnerability Details – OpenCVE
