Cybersecurity Blog | RedLegg

Security Bulletin: Citrix NetScaler ADC & NetScaler Gateway Authentication Bypass

Written by RedLegg's Cyber Threat Intelligence Team | 8/20/26, 9:04 PM

About:

CVE-2026-19490 is a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway deployments configured for Gateway or AAA services. The flaw could allow a remote attacker to bypass authentication without valid credentials, potentially gaining unauthorized access to affected appliances. While no active exploitation has been reported, organizations should treat remediation as a priority due to the severity of the vulnerability and the prevalence of NetScaler systems in remote access environments.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.

VULNERABILITIES

Authentication Bypass Using an Alternate Path in Citrix NetScaler ADC and NetScaler Gateway

Identifier: CVE-2026-19490
PoC or Exploitation: No known exploitation at this time.
CVSS Score: 9.3 (Critical, CVSS v4.0)

Update / Patch:
Cloud Software Group has released fixed versions addressing this vulnerability.

 Affected versions include:
  • NetScaler ADC and NetScaler Gateway, 14.1 through 73.32
  • NetScaler ADC and NetScaler Gateway, 13.1 through 63.21

The vulnerability applies when the appliance is configured as a Gateway such as SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server, subject to the following version-specific conditions:

  • 14.1-43.56 or later: applicable only when a SAML action is configured, in addition to Gateway or AAA vserver configuration
  • 14.1-66.68-FIPS or later: applicable only when a SAML action is configured, in addition to Gateway or AAA vserver configuration
  • 14.1-43.55 or earlier: applicable whenever Gateway or AAA vserver is configured
  • 13.1-61.28 or later: applicable only when a SAML action is configured
  • 13.1-61.27 or earlier: applicable whenever Gateway or AAA vserver is configured
  • 13.1 FIPS: applicable whenever Gateway or AAA vserver is configured
Fixed versions include:
  • NetScaler ADC and NetScaler Gateway 14.1-73.32 and later releases
  • NetScaler ADC and NetScaler Gateway 13.1-63.21 and later releases of 13.1
  • NetScaler ADC 14.1-FIPS: 14.1-73.32-FIPS and later releases
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.277 and later releases

Citrix Support Article CTX696939:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

Description:
CVE-2026-19490 is an authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway

The vulnerability allows a remote attacker without valid credentials or user interaction to bypass authentication on affected appliances.

Administrators can check whether an appliance is configured in an exploitable state by inspecting the NetScaler configuration for a SAML action configuration string and Auth or VPN vserver strings, as applicable to the firmware version in use.

Mitigation Recommendation:
Apply the applicable fixed version for your NetScaler ADC or Gateway deployment on an emergency basis.

Confirm your appliance's configuration against the version-specific applicability conditions above to determine your actual exposure.

Restrict access to the management interface so that it is reachable only from trusted networks or through a VPN until the update is fully deployed.

Monitor authentication logs on affected appliances for anomalous or unexpected authentication events which may indicate attempted exploitation.