← Vulnerability feed

Vulnerability record · CVE-2026-19490 · published 19 August 2026

CVE-2026-19490: Citrix NetScaler ADC and Gateway authentication bypass via alternate path

Citrix · Netscaler Application Delivery Controller

NetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable without credentials or user interaction and carries a CVSS 4.0 score of 9.3, so unauthenticated attackers can reach protected functionality directly. It affects ADC and Gateway releases 14.1 through 73.32 and 13.1 through 63.21.

9.3 CVSS 4.0 Critical CISA KEV since 9 Sep 2026 EPSS 7.0% · top 6.1% CWE-288 · Authentication bypass via alternate path
9.3CVSS 4.0 base score
7.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
10 Sep 2026Last modified by NVD

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priority

What it is

NetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable without credentials or user interaction and carries a CVSS 4.0 score of 9.3, so unauthenticated attackers can reach protected functionality directly. It affects ADC and Gateway releases 14.1 through 73.32 and 13.1 through 63.21.

Impact

An attacker gains full compromise of confidentiality, integrity and availability on the affected appliance, with limited follow-on impact to connected systems. Because these appliances front authentication and remote access, bypass can expose internal applications and sessions.

Attack surface

Reached over the network via the appliance's web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required; the record does not specify which endpoint or path is abused.

Exploitation

CVE-2026-19490 is listed in CISA KEV (added 2026-09-09, remediation due 2026-09-12), confirming exploitation in the wild. EPSS gives a 30-day probability of 0.05597 (92.5th percentile); no ransomware campaign use is documented.

What to do

  • Upgrade NetScaler ADC and Gateway to versions above 14.1-73.32 and 13.1-63.21 per Citrix advisory CTX696939; patch is the only complete fix.
  • If immediate patching is not possible, apply the vendor mitigations in CTX696939 and follow CISA BOD 26-04 guidance, including discontinuing use where no mitigation exists.
  • Restrict management and authentication interfaces from direct internet exposure where operationally feasible, and place them behind access controls.
  • Treat any unpatched, internet-facing appliance as compromised: rotate credentials and certificates and review sessions and configuration for unauthorized changes.
  • Track remediation against the CISA KEV due date of 2026-09-12 and report status under BOD 26-04.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on 9 September 2026 as "Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 12 September 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-19490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3519Citrix NetScaler ADC and Gateway unauthenticated code injectionCitrix NetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that allows unauthenticated remote code execution. The vendor bulle…KEVEPSS 100%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed9.3CVE-2025-5777Citrix NetScaler ADC/Gateway memory overread via insufficient input validationCVE-2025-5777 is an insufficient input validation flaw in Citrix NetScaler ADC and NetScaler Gateway that causes a memory overread when the appliance…KEVEPSS 100%analysed9.2CVE-2025-7775Citrix NetScaler memory overflow allows remote code executionNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that can lead to remote code execution or denial of service. It affect…KEVEPSS 20%analysed9.2CVE-2025-6543Citrix NetScaler ADC and Gateway memory overflow allows control flow hijack and DoSNetScaler ADC and NetScaler Gateway contain a memory buffer overflow (CWE-119) that causes unintended control flow and denial of service. It affects …KEVEPSS 11%analysed8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2023-6548Citrix NetScaler ADC and Gateway code injection enables low-privileged RCENetScaler ADC and NetScaler Gateway contain a code injection flaw (CWE-94) that lets an attacker with access to an NSIP, CLIP or SNIP management inte…KEVEPSS 3.2%analysed7.5CVE-2023-6549Citrix NetScaler ADC and Gateway out-of-bounds memory read and DoSNetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer (CWE-119), allowing an out-of-…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2026-19490), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.