Warning: Critical Authentication Bypass in Citrix NetScaler ADC & NetScaler Gateway, Patch Immediately!

By ccb.belgium.be
Publication Date: 2026-08-20 12:00:00

Last update: 20/08/2026

Affected software:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-63.21
  • NetScaler ADC FIPS before 14.1-73.32 FIPS
  • NetScaler ADC FIPS and NDcPP before 13.1-37.277

Additional Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities.

The appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server, subject to version-specific requirements.

Type: Authentication Bypass

CVE/CVSS: CVE-2026-19490: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)

Source

VendorCitrix

Risk

Citrix NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler…