By Tamilselvan
Publication Date: 2026-08-20 05:34:00
Cloud Software Group has issued an urgent security bulletin for two high-severity vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances, formerly known as Citrix ADC and Citrix Gateway.
Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could enable denial-of-service attacks or authentication bypass on vulnerable internet-facing appliances.
The issues pose a significant risk to organizations that depend on NetScaler Gateway for remote access, VPN connectivity, and application delivery.
Critical Citrix NetScaler Authentication Bypass Flaw
The most severe issue, CVE-2026-19490, has received a CVSS v4.0 score of 9.3 and is categorized as CWE-288, Authentication Bypass Using an Alternate Path.
An unauthenticated attacker could bypass access controls on affected NetScaler deployments configured as a Gateway for SSL VPN, ICA Proxy, Clientless VPN, or RDP Proxy services. The issue also affects appliances operating an AAA virtual server.

