Skip to main content

Active Exploitation of Citrix NetScaler ADC and NetScaler Gateway Vulnerability (CVE-2026-19490)

CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication


Threat details

Exploitation of CVE-2026-19490

Security researchers have reported exploitation of CVE-2026-19490 in the wild. CVE-2026-19490 has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as almost certain.

VPNs and other edge devices are internet-facing by design and are highly attractive targets to attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.


Introduction

Citrix published a security advisory addressing two vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication and CVE-2026-19489 could lead to unpredictable behaviour or denial of service.

  • CVE-2026-19490 - 'Authentication Bypass Using an Alternate Path' vulnerability - CVSSv4 score of 9.3
  • CVE-2026-19489 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 score of 8.8

End of life (EoL) products still vulnerable

NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End of Life (EoL) and are vulnerable. Organisations using EoL versions must upgrade to the latest release of supported versions as soon as possible.


Threat updates

Date Update
10 Sep 2026 Escalated to High Severity following reports of active exploitation

The following sections have been updated:

  • Severity
  • Title
  • Exploitation details
  • Remediation advice
  • Remediation steps
  • CVE identifier

Remediation advice

Affected organisations must review Citrix advisory CTX696939 and apply the relevant update as soon as possible.


Remediation steps

Type Step
Patch

Required: Update to a fixed version

Fixed versions include:

  • NetScaler ADC and NetScaler Gateway 14.1-73.32 and later releases

  • NetScaler ADC and NetScaler Gateway 13.1-63.21 and later releases of 13.1

  • NetScaler ADC 14.1-FIPS 14.1-73.32 FIPS and later releases of 14.1-FIPS

  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.277 and later releases of 13.1-FIPS and 13.1-NDcPP


https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939


Last edited: 10 September 2026 11:27 am