Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-19490)
CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication
Summary
CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-19490
Security researchers have reported exploitation of CVE-2026-19490 in the wild. CVE-2026-19490 has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses further exploitation as almost certain.
VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.
Introduction
Citrix published a security advisory addressing two vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication and CVE-2026-19489 could lead to unpredictable behaviour or denial of service.
- CVE-2026-19490 - 'Authentication Bypass Using an Alternate Path' vulnerability - CVSSv4 score of 9.3
- CVE-2026-19489 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 score of 8.8
End of life (EoL) products still vulnerable
NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End of Life (EoL) and are vulnerable. Organisations using EoL versions must upgrade to the latest release of supported versions as soon as possible.
Threat updates
| Date | Update |
|---|---|
| 10 Sep 2026 |
Escalated to High Severity following reports of active exploitation
The following sections have been updated:
|
Remediation advice
Affected organisations must review Citrix advisory CTX696939 and apply the relevant update as soon as possible.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Update to a fixed version Fixed versions include:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 10 September 2026 11:27 am