Last updated: August 21, 2026 at 10:03 AM UTC
All 747 Vulnerability 290 Breach 129 Threat 321 Defense 7
Tag: gateway (1 article)Clear

Critical Citrix NetScaler flaw lets attackers bypass authentication on gateways

Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.

Check
Upgrade NetScaler ADC and Gateway to the fixed builds immediately, and check your configuration for SAML action, gateway, and AAA virtual server entries to gauge exposure, treating edge appliances as priority targets.
Affected
Organizations running affected Citrix NetScaler ADC or Gateway as a gateway or AAA server (CVE-2026-19490); a remote, unauthenticated attacker can bypass authentication and reach internal services normally protected by it.
Fix
Patch to the fixed NetScaler versions, review configurations against Citrix's exposure criteria, monitor these appliances closely for compromise given their history as targets, and restrict management and gateway exposure where possible.