FR
live

Citrix NetScaler patches a critical remote authentication bypass (CVSS 9.3) exploitable without credentials

On August 19, 2026, Cloud Software Group published a bulletin for NetScaler ADC and NetScaler Gateway: CVE-2026-19490, a CVSS 9.3 authentication bypass exploitable remotely without credentials, and CVE-2026-19489, an 8.8 denial-of-service. Any internet-facing appliance needs an emergency upgrade, after triage driven by the SAML or vserver configuration.

A steel security gate left slightly ajar in a row of identical closed gates, a thin line of amber light spilling through the gap.

August 19, 2026, Cloud Software Group published bulletin CTX696939 for NetScaler ADC and NetScaler Gateway. At its center is CVE-2026-19490: an authentication bypass scored CVSS v4.0 9.3, exploitable remotely, with no credentials and no user interaction. CVE-2026-19489, a second flaw scored 8.8, completes the bulletin. For an appliance that holds the VPN front door for thousands of companies, either line alone justifies an emergency upgrade procedure.

What the flaw actually allows

CVE-2026-19490 is classified under CWE-288, Authentication Bypass Using an Alternate Path. In practice, an unauthenticated attacker can bypass access control on an appliance configured as a GatewaySSL VPN, ICA Proxy, CVPN, or RDP Proxy — or as an AAA virtual server. The exploitability perimeter depends on the installed build, and that distinction is what separates precise triage from blanket panic.

On NetScaler 14.1-43.56 and later, and 13.1-61.28 and later, the flaw is only exploitable when a SAML action is present in the configuration. On earlier builds, any Gateway or AAA vserver configuration is enough to expose the appliance. In other words, recent versions narrow the attack surface to SAML-federated deployments, while older ones leave the door open to any device doing VPN or authentication.

Citrix provides a way to check without scanning the network. The presence of any of these lines in the configuration indicates probable exposure:

bash
# SAML action configured (builds 14.1-43.56+ / 13.1-61.28+)
add authentication samlAction .*

# Authentication or VPN server present (earlier builds)
add authentication vserver .*
add vpn vserver .*

The flaw was reported by Samarth Vashisht of JPMorgan Chase’s penetration testing team — a reminder that auditing banks find these issues before criminal groups do, and that coordinated disclosure acts as the safety net for the global fleet.

The second flaw, quieter

CVE-2026-19489 is scored 8.8 and falls under CWE-119, an improper restriction of operations within the bounds of a memory buffer. It triggers when SIP ALG (the Session Initiation Protocol Application Layer Gateway) is enabled inside a LSN (Large Scale NAT) group configuration. Exploitation leads to unpredictable behavior or a full denial of service of the appliance.

The severity is lower, but the context is sneaky: SIP ALG is exactly the kind of option you turn on once for a telephony requirement and then forget. A NAT-terminating appliance that goes down takes remote-worker access with it, and an attacker who only wants to break service does not need to bypass anything at all.

Why it matters beyond the score

The scores are high, but what matters here is the appliance’s position. NetScaler ADC handles SSL termination, load balancing, and application security; NetScaler Gateway carries remote access and VPN. Both sit at the perimeter, often in a DMZ, exposed to the internet. An authentication bypass on this class of equipment is equivalent to neutralizing access control before ever reaching the internal network.

Recent history confirms it. CVE-2019-19781, the infamous « Shitrix », was mass-exploited within days of its January 2020 publication; CVE-2023-3519 followed the same script in 2023. Citrix appliances are among the most scanned targets on the internet the moment a bulletin drops. As of August 19, 2026, Rapid7 reports no observed active exploitation of CVE-2026-19490 — but that status rarely survives more than a few days for an authentication flaw on an edge device.

What to do now

The fixed versions are:

  • NetScaler ADC and Gateway 14.1: 14.1-73.32 and later.
  • NetScaler ADC and Gateway 13.1: 13.1-63.21 and later in the 13.1 branch.
  • NetScaler ADC 14.1-FIPS: 14.1-73.32 FIPS and later.
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP: 13.1-37.277 and later.

The bulletin covers only customer-managed instances. Cloud Software Group says it has already patched its cloud-managed services and its Adaptive Authentication offering. However, Secure Private Access Hybrid deployments that rely on self-managed NetScaler instances are affected and require the same upgrades.

The order of operations matters more than raw speed. First, inventory the appliances and determine each build; then triage with the commands above — a recent appliance without a SAML action remains vulnerable to CVE-2026-19489, but not to the critical flaw. Then patch, starting with internet-facing appliances, which are the target of automated scans. Finally, if an immediate upgrade is impossible, take the management interface off the internet and restrict VPN access to legitimate address ranges until the window opens.

Verdict

If you run an internet-connected NetScaler ADC or Gateway, move to 14.1-73.32+ or 13.1-63.21+ within 72 hours — the history of Citrix flaws says automated scanning follows the bulletin by days, not weeks. If your appliance is recent and has no SAML action, you are outside the CVE-2026-19490 perimeter but still affected by CVE-2026-19489: schedule the upgrade in the normal cycle rather than deferring it. And if you run Secure Private Access Hybrid, treat your instances as self-managed — the cloud-side fix does not cover you.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Medusa ransomware tops 500 critical infrastructure victims, CISA warns

On August 18, 2026, the FBI, CISA and HHS updated their joint advisory on the Medusa ransomware: more than 500 critical infrastructure victims since 2021, up from 300 in March 2025. Defenders need to patch the exploited flaws and segment networks before the gang does it for them.

Password spraying surges 155× in 2026 by slipping through MFA blind spots

Huntress measured a 155× increase in password spraying attacks in the first half of 2026, driven by an LSHIY campaign that generated 81 million login attempts in two weeks through the ROPC flow. Security teams must disable ROPC and extend MFA to every authentication flow, with no exceptions.

← Back to the feed

Type at least two characters.

navigate open esc dismiss