Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, auth-bypass, citrix, netscaler, critical, gateway] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: false

CVE-2026-19490 โ€” Citrix NetScaler Authentication Bypass

CVE-2026-19490 is a critical authentication-bypass vulnerability in customer-managed Citrix NetScaler ADC and NetScaler Gateway (CVSS 9.3), affecting FIPS and NDcPP builds as well as SecurAccess ZTNA-Hybrid deployments.

Details

Field Value
CVE CVE-2026-19490
CVSS 9.3 (Critical)
Product Citrix NetScaler ADC / NetScaler Gateway (customer-managed)
Type Authentication bypass
Fixed builds 14.1-73.32, 13.1-63.21 and equivalents
Exploitation None disclosed in the reporting window

Impact

NetScaler gateways and AAA appliances sit at the identity boundary of many enterprise estates. An auth-bypass on internet-facing deployments exposes the estate to takeover. Citrix-managed cloud services were already updated; affected customers should apply the fix in the same maintenance window as the accompanying guidance. The release also resolves the related memory-overflow issue CVE-2026-19489.

Source