By Rescana
Publication Date: 2026-09-14 00:00:00
Executive Summary
Citrix NetScaler ADC and NetScaler Gateway contain a critical authentication-bypass vulnerability, CVE-2026-19490, that allows an unauthenticated remote attacker to bypass authentication when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. Cloud Software Group (Citrix) disclosed the flaw on August 19, 2026 in security bulletin CTX696939, rating it CVSS v4.0 base 9.3 (CWE-288: Authentication Bypass Using an Alternate Path or Channel). NVD rates the same issue CVSS v3.1 9.8 and lists status Analyzed.
On September 9, 2026, CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation, with a federal remediation due date of September 12, 2026. The KEV record flags forensic triage required under BOD 26-04 as Yes; known ransomware campaign use remains Unknown. Security researchers and industry reporting cite exploitation in the wild from at least…



