Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Citrix NetScaler ADC and Gateway Authentication Bypass (CVE-2026-19490)

Catalog analysis: CISA added this entry on September 09, 2026. The entry reflects catalog information retrieved on September 09, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-19490 is an authentication bypass vulnerability (CWE-288) affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw involves an alternate path or channel that may allow an unauthenticated remote actor to bypass standard authentication mechanisms.

Exposure and applicability

This vulnerability does not affect all NetScaler deployments. It specifically applies to appliances configured in the following roles:
* AAA Virtual Server
* Gateway, including configurations for SSL VPN, ICA Proxy, CVPN, or RDP Proxy

Organizations utilizing these specific configurations as entry points for remote access are at higher risk of unauthenticated remote access.

Remediation priorities

Based on the vulnerability’s nature and its inclusion in the CISA Known Exploited Vulnerabilities catalog, we analyze the following prioritization strategy:

  1. Asset Identification: Immediately identify all NetScaler ADC and Gateway appliances and determine if they are configured as AAA virtual servers or Gateways. Assets with direct internet exposure should be prioritized for immediate mitigation.
  2. Vendor Mitigation Application: Apply the mitigations provided by Citrix according to their official instructions. This is the primary corrective action supported by the source to close the bypass path.
  3. Forensic Triage: Because this vulnerability allows authentication bypass, we recommend performing forensic triage on affected systems to determine if unauthorized access occurred prior to mitigation.

How to validate remediation

Verification must go beyond a simple version check or software inventory. To ensure exposure is reduced, defenders should:
* Verify Configuration State: Confirm that the specific AAA or Gateway roles are identified and that the vendor-supplied mitigations have been applied specifically to those functional paths.
* Validate Mitigation Application: Use vendor-provided tools or documentation to confirm the mitigation is active and functioning as intended on the appliance.

Confirmation of a software version alone does not prove that the vulnerability is mitigated if the specific configuration triggers the flaw or if the mitigation requires manual steps beyond a standard update.

Limits and open questions

There are several unknowns regarding this vulnerability. It is currently unknown whether this flaw has been utilized in known ransomware campaigns. Additionally, while CISA has provided a deadline for federal agencies, non-federal organizations must determine their own risk tolerance and patching timelines based on their specific exposure.

Residual risk remains if forensic triage is not completed, as the mitigation prevents future bypasses but does not remove actors who may have already gained access via this path.

Source and editorial note

CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability · Source date: September 09, 2026 · Retrieved September 09, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment