Citrix patches critical NetScaler authentication bypass CVE-2026-19490 in ADC and Gateway

Citrix has fixed a critical security flaw in NetScaler ADC and NetScaler Gateway that could let attackers get past login protections on internet-facing remote-access systems. The issue, CVE-2026-19490, is an authentication bypass via an alternative path affecting gateway and AAA virtual server deployments, including SSL VPN, ICA Proxy, CVPN, and RDP Proxy configurations; Citrix also fixed CVE-2026-19489, a high-severity memory overflow issue tied to SIP ALG in LSN group configurations. Fixed builds include 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS/NDcPP 13.1-37.277.
Why it matters: These appliances often sit at the edge of corporate networks and are reachable from the internet, so a login-bypass flaw can quickly become a high-impact intrusion path. Organizations using affected NetScaler deployments should treat this as an emergency patching issue and upgrade immediately.

Sources

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
info@thehackernews.com (The Hacker News) 2026.08.20 96% relevant
This article appears to cover the same underlying event: Citrix's disclosure of a critical authentication-bypass flaw in NetScaler affecting Gateway and AAA functionality, adding reporting context and affected deployment details rather than a distinct new incident.
Citrix urges admins to patch new NetScaler flaws as soon as possible
Sergiu Gatlan 2026.08.20 98% relevant
This article is the same underlying event: Citrix’s disclosure and patch guidance for CVE-2026-19490 in NetScaler ADC and Gateway. It adds practical detail on the second flaw CVE-2026-19489, the affected deployment conditions such as SAML and SIP ALG configurations, recommended fixed builds, and context that prior NetScaler flaws were quickly exploited after disclosure.
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Ionut Arghire 2026.08.20 100% relevant
This article establishes a distinct new patch-and-vulnerability story centered on Citrix's disclosure of CVE-2026-19490 and the expectation of near-term exploitation, not a previously tracked NetScaler event.
← Back to all stories