Skip to main content
QUIETLYTIC
Vulnerability

Citrix NetScaler ADC Authentication Bypass (CVE-2026-19490)

CVE-2026-19490 is a critical CVSS 9.8 authentication bypass in Citrix NetScaler ADC and Gateway, added to CISA's KEV catalog Sept. 9, 2026 as actively exploited.

CVE-2026-19490
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Citrix NetScaler ADC, Citrix NetScaler Gateway

CVE-2026-19490, a critical authentication bypass in Citrix NetScaler ADC and NetScaler Gateway, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, confirming active exploitation. NVD scores the flaw CVSS 3.1 base 9.8 (critical) — network-exploitable, no privileges or user interaction required.

What the vulnerability does

NVD classifies CVE-2026-19490 under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). Citrix’s own advisory (CTX696939, linked from NVD’s reference data) describes the affected versions as:

  • NetScaler ADC: 14.1 through 73.32, and 13.1 through 63.21
  • NetScaler Gateway: 14.1 through 73.32, and 13.1 through 63.21

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a network-reachable flaw requiring no authentication and no user interaction, with high impact to confidentiality, integrity, and availability if exploited — consistent with an authentication-bypass primitive against an internet-facing gateway appliance.

Why it’s on KEV

CISA added CVE-2026-19490 to the KEV catalog on September 9, 2026, which under Binding Operational Directive (BOD) 26-04 requires federal civilian agencies to apply mitigations by CISA’s specified deadline based on the assessed risk. CISA’s KEV entry directs affected organizations to Citrix’s advisory guidance and to evaluate each asset’s internet exposure directly, rather than publishing a fixed remediation timeline of its own.

What we don’t yet have

Our data pipeline has not yet corroborated this record with a second independent source — NVD and CISA KEV each contributed distinct fields (CVSS scoring and the base description from NVD; title, vendor/product identification, and KEV-listing metadata from CISA), but no field currently has two independent sources agreeing, so we’re marking overall confidence medium, not high. We also don’t yet have an EPSS exploitation-probability score or a specific exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild beyond the KEV listing itself) for this CVE — both are gaps in what we’ve ingested, not confirmed absences.

Why this matters

A pre-authentication bypass in an internet-facing VPN/application-delivery gateway is one of the highest-value targets in enterprise network attack chains — NetScaler sits at the network perimeter by design, so a successful bypass here can hand an attacker a foothold without needing any prior access. Combined with the KEV listing (meaning CISA has evidence of real-world exploitation, not just theoretical risk), organizations running NetScaler ADC or Gateway in the affected version ranges should treat this as an immediate patching priority rather than routine maintenance-window work.

Frequently Asked Questions

What is CVE-2026-19490? A critical (CVSS 9.8) authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway versions 14.1 through 73.32 and 13.1 through 63.21, tracked under CWE-288.

Is CVE-2026-19490 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, which CISA only does when it has evidence of active exploitation.

What should NetScaler administrators do? Apply Citrix’s fix per advisory CTX696939 and evaluate internet-facing exposure immediately, consistent with CISA’s BOD 26-04 guidance for KEV-listed vulnerabilities.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 10, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools