CVE-2026-19490: Critical Citrix NetScaler ADC & Gateway Auth Bypass — What to Do

Share
CVE-2026-19490: Critical Citrix NetScaler Flaw
5:53

A new critical vulnerability, CVE-2026-19490, lets a remote attacker bypass authentication on Citrix NetScaler ADC and NetScaler Gateway — the appliances many organizations rely on for remote access.

There is no confirmed exploitation in the wild yet, but NetScaler's history says the window to patch is short, and this post covers who is affected, what to do, and how to keep people connected while you do it.

What is CVE-2026-19490?

CVE-2026-19490 is a critical Citrix NetScaler vulnerability with a CVSS v4.0 base score of 9.3. It is an authentication bypass: a remote, unauthenticated attacker can circumvent login controls on affected appliances without credentials, user interaction, or elevated privileges. Citrix published the advisory and fixed builds on August 19, 2026.

The flaw is exposed on appliances acting as an access gateway or authentication server — precisely the roles that put NetScaler on the edge of a network handling remote logins.

Who is affected by this Citrix NetScaler vulnerability?

The vulnerability affects NetScaler ADC and NetScaler Gateway in these configurations:

  • Appliances configured as a Gateway — SSL VPN, ICA Proxy, Clientless VPN (CVPN), or RDP Proxy.

  • Appliances configured as an AAA virtual server.

Scope depends on build:

  • On newer builds (14.1-43.56 and later, 13.1-61.28 and later), the flaw is exploitable only when a SAML action is configured.
  • On earlier builds, any Gateway or AAA virtual server configuration is enough to expose it — a broader set of deployments.

Affected version families include NetScaler ADC and NetScaler Gateway 14.1 before build 73.32 and 13.1 before build 63.21, along with the FIPS and NDcPP variants.

Fixed versions and what to do now

Citrix has released fixed builds. Update affected appliances on an emergency basis:

Branch Fixed version
NetScaler ADC / Gateway 14.1 14.1-73.32 and later
NetScaler ADC / Gateway 13.1 13.1-63.21 and later
FIPS / NDcPP variants Corresponding FIPS/NDcPP fixed builds

 

Recommended steps:

  1. Identify appliances configured as a Gateway or AAA virtual server, and check whether a SAML action is in use.
  2. Patch to the fixed build for your branch.
  3. Because this is an authentication bypass, review sessions and logs for anomalies once patched — Citrix appliances have been targeted for session-token theft in past incidents.

As of the disclosure date, Rapid7 reported no evidence of active exploitation. That is not a reason to wait: Citrix gateways are high-value targets, and past critical flaws such as "CitrixBleed" (CVE-2023-4966) saw broad exploitation shortly after disclosure.

Why a single gateway appliance is a single point of failure

When remote access depends on one appliance line, a critical bug like this forces a hard choice: patch immediately and risk downtime, or stay online and risk exposure. Either way, one vendor's advisory dictates your maintenance window.

This is the case for a vendor-diverse remote-access posture. Running a second, software-defined VPN layer alongside your primary appliance means that when a critical Citrix NetScaler vulnerability lands, you can cut users over, patch calmly, and cut back — without an access outage.

A Citrix VPN alternative for continuity, not rip-and-replace

OpenVPN Access Server is a self-hosted VPN and ZTNA layer that runs on your own infrastructure, independent of any appliance vendor. As a Citrix VPN alternative or NetScaler alternative, it does not need to replace NetScaler to add value: kept warm as a disaster-recovery path, it gives your team a way to stay connected during forced patch windows and vendor incidents. For teams re-evaluating appliance dependence entirely, it can also serve as the primary secure-access layer.

The point is not that any one product is immune to vulnerabilities — none are. The point is that concentration risk is optional. A diverse access layer turns a critical-CVE fire drill into a routine patch.

Ready to see how OpenVPN can help protect your organization from attacks?

Try the self-hosted Access Server solution or managed CloudConnexa service for free — no credit card required.

See Which One is Right for You
 

Frequently Asked Questions

Is CVE-2026-19490 being actively exploited?

As of the August 19, 2026 disclosure, Rapid7 reported no evidence of exploitation in the wild. Given NetScaler's history of rapid exploitation after disclosure, treat patching as urgent.

How severe is CVE-2026-19490?

It carries a CVSS v4.0 base score of 9.3 (critical). It allows a remote, unauthenticated attacker to bypass authentication on affected NetScaler ADC and NetScaler Gateway appliances.

Which NetScaler versions are affected?

NetScaler ADC and NetScaler Gateway 14.1 before build 73.32 and 13.1 before build 63.21, plus the FIPS and NDcPP variants. Fixed builds are 14.1-73.32 and 13.1-63.21 and later.

How do I fix the Citrix NetScaler vulnerability?

Update affected appliances to the fixed build for your branch (14.1-73.32 or 13.1-63.21 or later), review whether Gateway/AAA and SAML actions are configured, and check logs for anomalous activity after patching.

What is a good Citrix VPN alternative for business continuity?

A software-defined, self-hosted VPN layer such as OpenVPN Access Server can run alongside an appliance as a disaster-recovery access path, so you can keep users connected during forced patch windows — or serve as a primary access layer if you want to reduce appliance dependence.

Related posts from OpenVPN

Subscribe for Blog Updates