Citrix patches critical NetScaler auth bypass CVE-2026-19490, exploitation expected
Citrix bulletin CTX696939 patches CVE-2026-19490, a CVSS 9.3 authentication bypass in customer-managed NetScaler ADC and Gateway. Fixed builds are 14.1-73.32 and 13.1-63.21. On 14.1-43.56+ and 13.1-61.28+ the bypass needs a SAML action. No confirmed in-the-wild exploitation yet.

Citrix patched a critical authentication bypass in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-19490 in bulletin CTX696939, published 19 August 2026. It is a CWE-288 flaw, authentication bypass using an alternate path, rated CVSS v4.0 9.3, exploitable remotely by an unauthenticated attacker. There are no workarounds. Rapid7, SecurityWeek and BleepingComputer all covered it.
CTX696939 carries two flaws. CVE-2026-19490 is the critical one: the CVSS 9.3 auth bypass on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers. The other, CVE-2026-19489, is a separate CWE-119 memory overflow rated CVSS 8.8, and it only bites when SIP ALG is enabled on a Large Scale NAT group.
Credit for the bug goes to Samarth Vashisht of JPMorgan Chase's penetration-testing team. The finding surfaced through defensive testing rather than an incident.
The fixed releases are NetScaler ADC and Gateway 14.1-73.32 and later, and 13.1-63.21 and later. For hardened deployments the floors are 14.1-73.32 FIPS and 13.1-37.277 FIPS/NDcPP.
On the newer builds, 14.1-43.56 and above or 13.1-61.28 and above, the bypass applies only when a SAML action is configured on the Gateway or AAA virtual server. On builds older than that, the exposure is broader: any Gateway or AAA virtual server, with no SAML gate at all.
Scope is customer-managed only. Cloud Software Group-managed cloud services and Adaptive Authentication are patched by the vendor. Secure Private Access Hybrid deployments that rely on a customer-managed NetScaler are in scope.
As of 19 August 2026, Rapid7 has not observed CVE-2026-19490 being exploited in the wild. SecurityWeek frames the risk as exploitation expected, not confirmed, because NetScaler is a high-value perimeter target that historically sees attacks land fast after disclosure.
What is measurable is the attack surface. BleepingComputer, citing Shadowserver on 20 August, counts more than 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances reachable on the internet. Shadowserver does not know which of those are on a patched build or running a SAML action. Rapid7 added a vulnerability check for CVE-2026-19490 to InsightVM, Nexpose and Exposure Command in its 20 August content release.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free