Skip to main content

Citrix Releases Security Updates for NetScaler ADC and NetScaler Gateway

CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication


Threat details

Introduction

Citrix published a security advisory addressing two vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication and CVE-2026-19489 could lead to unpredictable behaviour or denial of service.

  • CVE-2026-19490 - 'Authentication Bypass Using an Alternate Path' vulnerability - CVSSv4 score of 9.3
  • CVE-2026-19489 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 score of 8.8

Remediation advice

Affected organisations are strongly encouraged to review Citrix advisory CTX696939 and apply the relevant update as soon as possible.



Last edited: 19 August 2026 2:20 pm