Citrix patches critical NetScaler authentication bypass

Citrix released fixes for CVE-2026-19490 in NetScaler ADC and Gateway; Rapid7 warns unauthenticated remote attackers may exploit perimeter devices soon.

Citrix issued patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3. The vendor advised customers to upgrade affected systems immediately.

CVE-2026-19490 is an authentication bypass that can be reached via an alternative path on appliances configured as a gateway — including SSL VPN, ICA Proxy, CVPN and RDP Proxy — or as an AAA virtual server. Remote, unauthenticated attackers can exploit the flaw without any user interaction.

Citrix identified affected builds across the 14.1 and 13.1 release lines and published fixes in NetScaler ADC and Gateway builds 14.1-73.32 and 13.1-63.21, along with corresponding FIPS releases and specific 13.1 NDcPP updates. Administrators are directed to the vendor advisory for exact version mappings and upgrade instructions.

The vendor also patched CVE-2026-19489, a high-severity memory overflow that can cause unexpected behavior or a denial-of-service when SIP ALG is enabled in an LSN group. Citrix said Secure Private Access Hybrid deployments that use NetScaler instances are affected and should be updated to the recommended builds.

Security firm Rapid7 reported no confirmed exploitation of the authentication bypass at the time of its advisory but warned NetScaler appliances are commonly deployed at or near enterprise perimeters and are often reachable from the public internet. Rapid7 recommended organizations prioritize emergency patching because externally accessible NetScaler devices are attractive targets.

Where immediate patching is not possible, administrators are advised to limit public access to NetScaler management interfaces, monitor logs and network activity for signs of abuse, and schedule upgrades to the fixed releases as soon as feasible.

Articles by this author