Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-19490

Critical authentication bypass in Citrix NetScaler ADC and Gateway

Unauthenticated auth bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) allows remote exploitation with no user interaction. Patches released August 19, 2026 for 13.1 and 14.1 branches.

cat cve-2026-19490.json
Vendor
Citrix
Product
NetScaler ADC, NetScaler Gateway
CVSS
9.3
EPSS (exploit probability)
N/A
Status
patched
Published

An unauthenticated authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, carrying a CVSS v4.0 base score of 9.3. An attacker can reach the flaw remotely with no user interaction and no elevated privileges required — the full trifecta for a network-edge product.

Affected Versions

Product Vulnerable if running Fixed in
NetScaler ADC/Gateway 14.1 Prior to 14.1-73.32 14.1-73.32
NetScaler ADC/Gateway 13.1 Prior to 13.1-63.21 13.1-63.21
NetScaler ADC FIPS 14.1 Prior to 14.1-73.32 FIPS 14.1-73.32 FIPS
NetScaler ADC 13.1-FIPS/NDcPP Prior to 13.1-37.277 13.1-37.277

Mitigation

No workaround listed. Update to the fixed release for your branch. Citrix’s advisory CTX696939 is the authoritative patch guidance. Prioritize internet-facing Gateway appliances first.

As of August 19, 2026, no exploitation in the wild has been confirmed per Rapid7’s early technical assessment. Given the class of vulnerability and the perimeter position of these products, that status should be treated as time-limited.