Citrix Patches Critical NetScaler Auth Bypass
Citrix patches CVE-2026-19490, critical auth bypass in NetScaler ADC and Gateway, CVSS 9.3. No exploitation observed yet — here's what to patch before that changes.

Citrix published patches on August 19 for CVE-2026-19490, a critical authentication bypass in NetScaler ADC and NetScaler Gateway. CVSS v4.0 base score: 9.3. An unauthenticated attacker can reach it remotely with no user interaction and no elevated privileges. These products sit at the edge of enterprise networks. Patch them.
What’s Vulnerable
The flaw affects both the 13.1 and 14.1 branches of NetScaler ADC and Gateway, including FIPS and NDcPP variants:
| Product | Vulnerable if running | Fixed in |
|---|---|---|
| NetScaler ADC/Gateway 14.1 | Prior to 14.1-73.32 | 14.1-73.32 |
| NetScaler ADC/Gateway 13.1 | Prior to 13.1-63.21 | 13.1-63.21 |
| NetScaler ADC FIPS 14.1 | Prior to 14.1-73.32 FIPS | 14.1-73.32 FIPS |
| NetScaler ADC 13.1-FIPS/NDcPP | Prior to 13.1-37.277 | 13.1-37.277 |
NetScaler ADC and Gateway sit at or near the network perimeter — handling VPN access, application delivery, and load balancing for enterprise traffic. An unauthenticated authentication bypass at that layer means the gateway isn’t doing its job.
Rapid7’s early technical assessment found no in-the-wild exploitation as of August 19. That has a short shelf life. Citrix NetScaler products have a documented pattern of rapid exploitation after advisory disclosure — the previous major NetScaler flaw, Citrix Bleed, went from advisory to mass exploitation campaigns within days.
What to Do
No workaround listed. Patch.
- Identify your running versions across your ADC and Gateway fleet using the table above.
- Update to the fixed release for your branch. All fixed versions are available now per the Citrix advisory CTX696939.
- Prioritize internet-facing Gateway appliances first — these are directly exposed to unauthenticated remote traffic and highest-risk.
Priority Call
Patch this before the weekend. CVSS 9.3, unauthenticated, remote, no interaction required — this is exactly the class of vulnerability that gets weaponized fast once a PoC circulates. If you’re running an unpatched NetScaler at your perimeter by next week, that’s a deliberate risk acceptance, not an oversight.
Check the Citrix security advisory CTX696939 directly for any updates as this develops.
- [ CRITICAL ]CVE-2026-19490Critical authentication bypass in Citrix NetScaler ADC and Gateway
Found this useful? Share it.
