Skip to content
feed: live
>_0dayNews
citrix

Citrix NetScaler Auth Bypass Now Exploited in Wild

Attackers are actively targeting CVE-2026-19490, a critical auth bypass in Citrix NetScaler ADC and Gateway. Patches have been available since August 19.

Citrix NetScaler Auth Bypass Now Exploited in Wild
Photo: Coolcaesar at en.wikipedia / Wikimedia Commons · CC BY-SA 3.0
kilobaudDave "Kilobaud" Ferris·Published ·1 min read

Attackers have begun targeting CVE-2026-19490, the critical authentication bypass in Citrix NetScaler ADC and NetScaler Gateway that Citrix patched on August 19. Vulnerability intelligence firm Previdian confirmed active exploitation Thursday, per BleepingComputer.

The flaw carries a CVSS v4.0 base score of 9.3. Unauthenticated, remote, no user interaction required. We noted at the time that Citrix perimeter products have a documented pattern of rapid weaponization after advisory disclosure. Sixteen days, as it turned out.

What’s at risk

NetScaler ADC and NetScaler Gateway sit at or near the network perimeter, handling VPN access, application delivery, and load balancing for enterprise traffic. An authentication bypass at that layer means an unauthenticated attacker can reach functionality that should require credentials.

Affected versions and their fixed counterparts:

Product Vulnerable if running Fixed in
NetScaler ADC/Gateway 14.1 Prior to 14.1-73.32 14.1-73.32
NetScaler ADC/Gateway 13.1 Prior to 13.1-63.21 13.1-63.21
NetScaler ADC FIPS 14.1 Prior to 14.1-73.32 FIPS 14.1-73.32 FIPS
NetScaler ADC 13.1-FIPS/NDcPP Prior to 13.1-37.277 13.1-37.277

What to do

If you haven’t patched: the authoritative guidance is Citrix advisory CTX696939. Update to the fixed release for your branch. Internet-facing Gateway appliances first, everything else after.

If you patched in August: check your logs for anomalous authentication activity between August 19 and your patch date. An exploited auth bypass does not always surface immediately.

There is no workaround for CVE-2026-19490. The fix is the patch.

The Citrix pattern

Citrix NetScaler products have a short window between advisory and active exploitation. Citrix Bleed went from disclosure to mass exploitation in days; CVE-2026-8452 landed in the CISA KEV catalog within weeks of its patch. CVE-2026-19490 has now followed.

If your organization runs NetScaler appliances and your standard patch cycle runs longer than two to three weeks, these products probably belong in a faster maintenance tier.

Related CVEs
  • [ CRITICAL ]CVE-2026-19490Critical authentication bypass in Citrix NetScaler ADC and Gateway

Found this useful? Share it.