type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, auth-bypass, citrix, netscaler, critical, gateway] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: false
CVE-2026-19490 โ Citrix NetScaler Authentication Bypass
CVE-2026-19490 is a critical authentication-bypass vulnerability in customer-managed Citrix NetScaler ADC and NetScaler Gateway (CVSS 9.3), affecting FIPS and NDcPP builds as well as SecurAccess ZTNA-Hybrid deployments.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-19490 |
| CVSS | 9.3 (Critical) |
| Product | Citrix NetScaler ADC / NetScaler Gateway (customer-managed) |
| Type | Authentication bypass |
| Fixed builds | 14.1-73.32, 13.1-63.21 and equivalents |
| Exploitation | None disclosed in the reporting window |
Impact
NetScaler gateways and AAA appliances sit at the identity boundary of many enterprise estates. An auth-bypass on internet-facing deployments exposes the estate to takeover. Citrix-managed cloud services were already updated; affected customers should apply the fix in the same maintenance window as the accompanying guidance. The release also resolves the related memory-overflow issue CVE-2026-19489.