Critical Citrix NetScaler Authentication Bypass Flaw Exposes Gateway Appliances

Critical Citrix NetScaler Authentication Bypass Flaw Exposes Gateway Appliances

By Tamilselvan
Publication Date: 2026-08-20 05:34:00

Cloud Software Group has issued an urgent security bulletin for two high-severity vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances, formerly known as Citrix ADC and Citrix Gateway.

Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could enable denial-of-service attacks or authentication bypass on vulnerable internet-facing appliances.

The issues pose a significant risk to organizations that depend on NetScaler Gateway for remote access, VPN connectivity, and application delivery.

Critical Citrix NetScaler Authentication Bypass Flaw

The most severe issue, CVE-2026-19490, has received a CVSS v4.0 score of 9.3 and is categorized as CWE-288, Authentication Bypass Using an Alternate Path.

An unauthenticated attacker could bypass access controls on affected NetScaler deployments configured as a Gateway for SSL VPN, ICA Proxy, Clientless VPN, or RDP Proxy services. The issue also affects appliances operating an AAA virtual server.