By Abinaya
Publication Date: 2026-09-10 13:23:00
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026.
CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a Gateway service. This includes deployments supporting SSL VPN, ICA Proxy, CVPN, and RDP Proxy functions.
The flaw is categorized as CWE-288, Authentication Bypass Using an Alternate Path or Channel. It could allow a remote, unauthenticated attacker to bypass login protections and access functionality that normally requires valid credentials.
Because NetScaler appliances are commonly deployed at the edge of corporate networks to provide remote access, successful exploitation could expose sensitive applications and internal services.
Citrix released…



