Critical Citrix NetScaler Auth Bypass CVE-2026-19490 Targeted in Attacks

Server Security

Attackers have begun targeting CVE-2026-19490, a critical authentication-bypass vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway deployments.

Previdian reported observing exploitation attempts on September 3, one day after public proof-of-concept activity was recorded. The vulnerability carries a CVSS v4.0 score of 9.3 and can allow a remote, unauthenticated attacker to circumvent authentication controls on affected appliances.

Citrix disclosed and patched the flaw on August 19. The new exploitation evidence changes the operational priority: administrators should now treat exposed and vulnerable Gateway or AAA deployments as an emergency patching case rather than a routine maintenance item.

9.3
CVSS v4.0 severity score
No auth
Required for exploitation
No workaround
Citrix requires an upgrade

Which NetScaler Deployments Are Exposed?

CVE-2026-19490 is an authentication bypass through an alternate path. An appliance must be configured as a Gateway — including SSL VPN, ICA Proxy, CVPN or RDP Proxy — or as an AAA virtual server. The precise exposure conditions depend on the installed NetScaler build.

For NetScaler 14.1 builds 14.1-43.56 and later, and 13.1 builds 13.1-61.28 and later, the vulnerable configuration also requires a SAML action. Earlier builds can be affected when configured as a Gateway or AAA virtual server even without that additional condition.

Secure Private Access Hybrid deployments using affected NetScaler instances are also included. The bulletin applies to customer-managed NetScaler ADC and Gateway systems. Citrix says it has already updated Citrix-managed cloud services and Citrix-managed Adaptive Authentication.

Configuration check:
Citrix advises administrators to inspect configurations for
add authentication samlAction,
add authentication vserver and
add vpn vserver entries when determining whether an appliance meets the vulnerability preconditions.

Fixed NetScaler Builds

Citrix says affected customers should install the relevant fixed build as soon as possible. The vendor lists no workaround or mitigating configuration that can replace the update.

Product branch Affected builds Fixed build
NetScaler ADC and Gateway 14.1 Before 14.1-73.32 14.1-73.32 or later
NetScaler ADC and Gateway 13.1 Before 13.1-63.21 13.1-63.21 or later
NetScaler ADC 14.1 FIPS Before 14.1-73.32 FIPS 14.1-73.32 FIPS or later
NetScaler ADC 13.1 FIPS and NDcPP Before 13.1-37.277 13.1-37.277 or later

Exploitation Has Been Observed, but the Evidence Is Limited

Previdian says its sensors observed requests matching exploitation of CVE-2026-19490. The company initially reported six attempts from four attacker IP addresses across three countries, with one sensor recording the activity. It rated its exploitation assessment at medium confidence.

That is evidence of active targeting, but it does not establish the number of successfully compromised organizations or prove a large-scale campaign. CVE-2026-19490 was not listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog when Previdian published its report.

The Canadian Centre for Cyber Security issued a separate alert on September 4 and recommended emergency patching, particularly for Internet-facing appliances and SAML-configured systems. It also advised organizations to monitor authentication logs and network activity for unauthorized access.

What Administrators Should Do Now

Operators should inventory customer-managed NetScaler ADC and Gateway appliances, identify their exact versions and determine which systems expose Gateway or AAA services. Relevant SAML configurations should be checked against the version-specific conditions in Citrix’s bulletin.

Affected appliances should then be upgraded to the appropriate fixed build. After updating, administrators should confirm the running version and review authentication records, administrative changes and network activity for signs of access that cannot be linked to legitimate users.

Patching closes the vulnerability but does not remove evidence of an earlier compromise. Organizations that find suspicious activity should follow Citrix’s incident-response guidance and investigate the affected appliance rather than assuming the software update alone resolves the incident.