News

Citrix patches critical NetScaler auth bypass CVE-2026-19490, exploitation expected

Citrix bulletin CTX696939 patches CVE-2026-19490, a CVSS 9.3 authentication bypass in customer-managed NetScaler ADC and Gateway. Fixed builds are 14.1-73.32 and 13.1-63.21. On 14.1-43.56+ and 13.1-61.28+ the bypass needs a SAML action. No confirmed in-the-wild exploitation yet.

Citrix patches critical NetScaler auth bypass CVE-2026-19490, exploitation expected

Citrix patched a critical authentication bypass in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-19490 in bulletin CTX696939, published 19 August 2026. It is a CWE-288 flaw, authentication bypass using an alternate path, rated CVSS v4.0 9.3, exploitable remotely by an unauthenticated attacker. There are no workarounds: patching is the only fix. Rapid7, SecurityWeek and BleepingComputer all covered it.

The instrument: CVE-2026-19490, and the second CVE it is not

CTX696939 carries two flaws, and collapsing them is the first mistake to avoid. CVE-2026-19490 is the critical one: the CVSS 9.3 auth bypass on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers. The other, CVE-2026-19489, is a separate CWE-119 memory overflow rated CVSS 8.8, and it only bites when SIP ALG is enabled on a Large Scale NAT group. Different weakness, different precondition, different severity. If you are triaging, 19490 is the perimeter emergency; 19489 is a conditional denial-of-service on a narrower config.

Credit for the bug goes to Samarth Vashisht of JPMorgan Chase's penetration-testing team, which is a reminder that this surfaced through defensive testing rather than an incident.

The fixed builds, and the SAML gate that decides your exposure

The numbers that are not in the headline are the build strings, and you cannot act without them. The fixed releases are NetScaler ADC and Gateway 14.1-73.32 and later, and 13.1-63.21 and later. For hardened deployments the floors are 14.1-73.32 FIPS and 13.1-37.277 FIPS/NDcPP. Treat those as the minimum, not a suggestion.

Whether you are even in scope for 19490 turns on one detail. On the newer builds, 14.1-43.56 and above or 13.1-61.28 and above, the bypass applies only when a SAML action is configured on the Gateway or AAA virtual server. On builds older than that, the exposure is broader: any Gateway or AAA virtual server, with no SAML gate at all. So a shop that assumes SAML-only immunity while running an older firmware is reading the wrong row. Check your build first, then check for a SAML action, in that order.

Scope is customer-managed only. Cloud Software Group-managed cloud services and Adaptive Authentication are patched by the vendor, so those customers do nothing. But Secure Private Access Hybrid deployments that rely on a customer-managed NetScaler are in scope, which catches teams who assume a managed product covers the appliance underneath it.

The exposure is large, but nobody has confirmed exploitation yet

This is where the headline has to stay honest. As of 19 August 2026, Rapid7 has not observed CVE-2026-19490 being exploited in the wild. SecurityWeek frames the risk as exploitation expected, not confirmed, because NetScaler is a high-value perimeter target that historically sees attacks land fast after disclosure. Those are two different states. "Expected" is a forecast; "actively exploited" is an observation, and no vendor is making the second claim today.

What is measurable is the attack surface. BleepingComputer, citing Shadowserver on 20 August, counts more than 22,000 NetScaler ADC instances and nearly 1,800 NetScaler Gateway instances reachable on the internet. Read that as exposure, not confirmed-vulnerable: Shadowserver does not know which of those are on a patched build or running a SAML action. On the detection side, Rapid7 added a vulnerability check for CVE-2026-19490 to InsightVM, Nexpose and Exposure Command in its 20 August content release, so scanning for it is now a scheduled task rather than a manual hunt.

The takeaway

If you run customer-managed NetScaler ADC or Gateway, treat 14.1-73.32 and 13.1-63.21 (or the matching FIPS builds) as the floor today, because there is no workaround to buy you time. Before you conclude you are out of scope on a newer build, confirm two things in this order: that you are actually on 14.1-43.56+ or 13.1-61.28+, and that no SAML action sits on your Gateway or AAA virtual server. On older firmware, skip the SAML question, because the bypass does not need it. And do not wait for someone to publish an in-the-wild report: the honest status is exploitation expected, and on a Citrix perimeter box that has been the reliable precursor to it landing.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free