By Divya
Publication Date: 2026-08-20 05:53:00
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances.
Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches.
Citrix NetScaler Flaw
The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and is classified as CWE-288, which refers to “Authentication Bypass Using an Alternate Path.”
This flaw could enable a remote, unauthenticated attacker to bypass authentication controls when the vulnerable appliance is configured as a Gateway or AAA virtual server under specific conditions.
This issue is particularly concerning because NetScaler Gateway deployments often serve as the entry point to enterprise networks, providing access to SSL VPN, ICA Proxy, CVPN, and RDP Proxy.
A successful authentication bypass in such settings could allow an attacker to access…

