Citrix Releases Security Updates for NetScaler ADC and NetScaler Gateway
CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication
Summary
CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Citrix published a security advisory addressing two vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Successful exploitation of CVE-2026-19490 could allow a remote unauthenticated attacker to bypass authentication and CVE-2026-19489 could lead to unpredictable behaviour or denial of service.
- CVE-2026-19490 - 'Authentication Bypass Using an Alternate Path' vulnerability - CVSSv4 score of 9.3
- CVE-2026-19489 - 'Improper Restriction of Operations within the Bounds of a Memory Buffer' vulnerability - CVSSv4 score of 8.8
Remediation advice
Affected organisations are strongly encouraged to review Citrix advisory CTX696939 and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 19 August 2026 2:20 pm