As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
On August 19, 2026, Citrix released a security advisory for CVE-2026-19490, a critical authentication bypass vulnerability (CVSS 9.3) affecting NetScaler ADC and NetScaler Gateway versions prior to 14.1-73.32 and 13.1-63.21. An unauthenticated attacker can exploit this remotely over the network without user interaction. As of the advisory date, no active exploitation in the wild has been observed, but Citrix products are frequent targets for rapid weaponization after vulnerability disclosure.
Why it matters: Organizations running exposed NetScaler ADC or Gateway appliances must apply emergency patches immediately: this critical authentication bypass on perimeter-facing systems creates immediate risk for remote unauthorized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
On August 19, 2026, Citrix released a security advisory for CVE-2026-19490, a critical authentication bypass vulnerability (CVSS 9.3) affecting NetScaler ADC and NetScaler Gateway versions prior to 14.1-73.32 and 13.1-63.21. An unauthenticated attacker can exploit this remotely over the network without user interaction. As of the advisory date, no active exploitation in the wild has been observed, but Citrix products are frequent targets for rapid weaponization after vulnerability disclosure.
Why it matters: Organizations running exposed NetScaler ADC or Gateway appliances must apply emergency patches immediately: this critical authentication bypass on perimeter-facing systems creates immediate risk for remote unauthorized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix released a security advisory on August 19, 2026 for CVE-2026-19490, an authentication bypass flaw with a CVSS score of 9.3 affecting NetScaler ADC and NetScaler Gateway across multiple versions. The vulnerability allows unauthenticated remote attackers to bypass authentication with no user interaction required, posing significant risk to organizations that expose these perimeter devices to the internet.
Why it matters: Enterprise teams running affected NetScaler ADC or Gateway versions must apply emergency patches immediately, as these high-value targets commonly see rapid exploitation once vulnerabilities become public; verify your configurations for SAML actions and authentication or virtual private network (VPN) vservers to determine exposure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
CVE-2026-19490 is a critical authentication bypass vulnerability with a CVSS score of 9.3 affecting Citrix NetScaler ADC and NetScaler Gateway versions 13.1 and 14.1. The flaw allows unauthenticated remote attackers to bypass authentication without user interaction or elevated privileges on systems commonly exposed to the internet. Citrix has released patched versions (14.1-73.32, 13.1-63.21, and others) and organizations should apply updates immediately, as Citrix products are high-value targets historically exploited quickly after vulnerability disclosure.
Why it matters: Enterprises running NetScaler ADC or Gateway in perimeter networks must patch immediately: this authentication bypass affects widely deployed load balancers and virtual private network (VPN) appliances that control critical traffic, and threat actors routinely exploit Citrix vulnerabilities once details become public.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix released a security advisory on August 19, 2026 for CVE-2026-19490, a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway with a CVSS v4.0 score of 9.3. The flaw allows unauthenticated remote attackers to bypass authentication without user interaction and affects multiple product versions; Rapid7 has not yet observed active exploitation, but organizations should patch on an emergency basis given the high-value nature of these perimeter-deployed systems.
Why it matters: Administrators managing Citrix NetScaler ADC or NetScaler Gateway must immediately apply patches for affected versions (14.1 prior to 14.1-73.32, 13.1 prior to 13.1-63.21, and FIPS variants) because unauthenticated attackers can bypass authentication on internet-exposed appliances, and historical patterns show Citrix authentication vulnerabilities are quickly exploited in the wild.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix released a security advisory on August 19, 2026 for CVE-2026-19490, a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway with a CVSS v4.0 score of 9.3. The flaw allows unauthenticated remote attackers to bypass authentication without user interaction and affects multiple product versions; Rapid7 has not yet observed active exploitation, but organizations should patch on an emergency basis given the high-value nature of these perimeter-deployed systems.
Why it matters: Administrators managing Citrix NetScaler ADC or NetScaler Gateway must immediately apply patches for affected versions (14.1 prior to 14.1-73.32, 13.1 prior to 13.1-63.21, and FIPS variants) because unauthenticated attackers can bypass authentication on internet-exposed appliances, and historical patterns show Citrix authentication vulnerabilities are quickly exploited in the wild.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
Citrix released a security advisory on August 19, 2026, for CVE-2026-19490, a critical authentication bypass vulnerability in NetScaler ADC and NetScaler Gateway with a CVSS score of 9.3. The flaw allows remote unauthenticated attackers to exploit these perimeter-deployed products without user interaction or elevated privileges. Fixed versions are available, and organizations should patch affected systems immediately.
Why it matters: Enterprise security teams managing Citrix NetScaler products exposed to the internet face immediate risk of unauthorized access, as these high-value targets typically see rapid exploitation once public details emerge.
- Source published
- First seen by Cybersecurity Tracker