By SOC Prime Team
Publication Date: 2026-08-20 15:01:00
Cloud Software Group has released security updates for a critical authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-19490 and rated 9.3 on the CVSS v4.0 scale, the flaw can allow an unauthenticated remote attacker to circumvent authentication controls on vulnerable systems configured as gateways or AAA virtual servers.
The Critical Citrix NetScaler Authentication Bypass Flaw is particularly concerning because NetScaler Gateway appliances frequently operate at the edge of enterprise networks, providing SSL VPN and other remote-access functionality. Successful exploitation could give an attacker access to protected services without requiring legitimate credentials or user interaction.
CVE-2026-19490 carries a CVSS vector indicating network-based exploitation, low attack complexity, no privileges, and no user interaction, with potentially high impact to confidentiality, integrity, and…

