Citrix patched a critical authentication bypass in NetScaler ADC and NetScaler Gateway on 19 August 2026. CERT-SE published its own advisory the following day and added an instruction that Citrix’s bulletin does not contain, as well as updating, examine systems carefully for signs of intrusion.
The flaw, CVE-2026-19490, carries a CVSS v4.0 score of 9.3. It lets an attacker skip login checks through an alternate path with no credentials, no user interaction and no elevated privileges required. Cloud Software Group, Citrix’s parent company, credited Samarth Vashisht of JPMorgan Chase’s penetration-testing team with reporting it.
The fixed builds are NetScaler ADC and NetScaler Gateway 14.1-73.32 and 13.1-63.21 with 14.1-73.32 FIPS and 13.1-37.277 covering the FIPS and NDcPP branches. Anything on 14.1 before 14.1-73.32 or 13.1 before 13.1-63.21 is in scope. Citrix-managed cloud services and Adaptive Authentication were patched by Citrix and need no customer action.
Three Config Strings Tell You Whether You Are Exposed
Not every NetScaler is affected. The preconditions are narrow enough to be worth checking before anyone books an emergency change window. The appliance has to be running as a Gateway covering SSL VPN, ICA Proxy, CVPN or RDP Proxy or as an AAA virtual server.
On newer affected builds a SAML action also has to be configured. On older firmware the Gateway or AAA configuration alone is enough with no SAML involved at all. The version thresholds differ between standard and FIPS builds, which is where most self-assessments go wrong.
Anil Shetty, senior VP of Engineering at Cloud Software Group, pointed teams at three configuration strings. Search the running config for add authentication samlAction to spot a SAML setup and for add authentication vserver or add vpn vserver to spot an Auth or VPN virtual server. That check takes less time than raising the change ticket.
The Cloud Marketplace Images Were Not Refreshed
Citrix noted that when its advisory went out, the NetScaler images listed on the AWS, Azure and GCP marketplaces had not yet been updated with the patched builds.
That detail has had less attention than it deserves. A team that deploys NetScaler from a cloud marketplace and treats the latest image as the current version will patch a running appliance, then rebuild straight back into a vulnerable one during the next scale-out or disaster-recovery test. Citrix’s instruction is to pull the fixed builds from its own downloads page instead.
CERT-SE Describes This More Severely Than Citrix Does
CERT-SE’s advisory on 20 August states that successful exploitation can let an unauthenticated attacker execute arbitrary code remotely. Citrix’s own bulletin describes an authentication bypass which is not the same thing.
The gap matters when you are deciding how hard to push internally. Plan against the more severe reading. A national CSIRT choosing stronger language than the vendor is a signal rather than a translation slip and CERT-SE’s second recommendation follows from it, look for evidence of intrusion, do not just apply the update and close the ticket.
The Second Flaw Needs SIP ALG Turned On
CVE-2026-19489, a memory overflow scored 8.8 on CVSS v4.0, can cause unpredictable behaviour or denial of service. It applies only where SIP ALG is enabled on a Large Scale NAT group. Search the configuration for add lsn group together with sipalg to confirm.
Most enterprise deployments will not meet that condition. Carrier and service-provider deployments are a different matter.
Rapid7 said on 19 August that it had not observed exploitation of CVE-2026-19490 and urged organisations to prioritise patching on an emergency basis regardless, on the grounds that Citrix products draw exploitation quickly once details are public. That statement is a dated snapshot, not a forecast.
One operational note before the work is scheduled. Citrix warns that after a NetScaler in an ICA proxy setup is upgraded to 14.1-72.16 or 13.1-63.18 or later, any ICA session reconnecting with a session ticket issued by the pre-upgrade build is dropped and users have to launch the session again. That is intended behaviour, not a fault. Tell the service desk before the change window, not during it.
References
- Citrix Urges Customers To Fix Critical NetScaler Authentication Bypass
- Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway
- Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- NetScaler ADC and NetScaler Gateway Vulnerabilities
- Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
This post is also available in:
