AI description
CVE-2026-19490 is an authentication bypass vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw, classified as CWE-288: Authentication Bypass Using an Alternate Path, allows an unauthenticated remote attacker to circumvent authentication controls on vulnerable systems. The vulnerability specifically affects appliances configured as a Gateway (such as SSL VPN, ICA Proxy, Clientless VPN/CVPN, or RDP Proxy) or as an AAA virtual server. For newer vulnerable builds, exploitation may require a SAML action to be configured, while older builds have a broader attack surface where the Gateway or AAA configuration alone is sufficient. Successful exploitation of CVE-2026-19490 could grant an attacker unauthorized access to internal applications and services that are typically secured behind authentication boundaries, without needing valid credentials or user interaction. The affected versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32, and 13.1 before 13.1-63.21, along with corresponding FIPS and NDcPP releases. Cloud Software Group, the vendor, has released security updates and strongly recommends that customers upgrade affected customer-managed NetScaler appliances immediately.
- Description
- Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
- Source
- 50a63c94-1ea7-4568-8c11-eb79e7c5a2b5
- NVD status
- Undergoing Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Exploit added on
- Sep 9, 2026
- Exploit action due
- Sep 12, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-288
- Hype score
- Not currently trending
🔒 #CyberSecurity CISA KEV Adds CVE-2025-25249, CVE-2026-19490, CVE-2026-87491, CVE-2026-20079: F… "On September 9, 2026, CISA added four vulnerabilities to its Known Exploited Vulnerabilities…" 🔗 https://t.co/U9Ok5n6M9t #CyberSecurity #ThreatIntel #critical #zeroday
@SecurityAr58409
10 Sept 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 NetScaler ADC/Gateway, Authentication Bypass, #CVE-2026-19490 (Critical) -DC-Sep2026-2301 https://t.co/aBhYjJJ9pQ
@dailycve
10 Sept 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2025-25249 (Fortinet複数製品) - CVE-2026-19490 (Citrix Netscaler) - CVE-2026-87491 (Chromium) - CVE-2026-20079 (Cisco
@__kokumoto
9 Sept 2026
732 Impressions
1 Retweet
9 Likes
4 Bookmarks
1 Reply
0 Quotes
Citrix NetScaler CVE-2026-19490 (CVSS 9.3) auth bypass faces live probes after a public PoC. Patch ADC/Gateway to 14.1-73.32 or 13.1-63.21. Check Gateway/AAA configs. https://t.co/118bW3j8X9
@snakeyesV1
8 Sept 2026
83 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Hackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler. Update your systems immediately. #CitrixNetScaler #CyberSecurity #Vulnerability #NetworkSecurity #Infosec https://t.co/usUAO9jSQq
@Daily_CyberSec
7 Sept 2026
315 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🚨 Citrix NetScaler #CVE-2026-19490 Critical Authentication Bypass: Active Probing Triggers Emergency Patching Response + Video -Prediction: 📈 2 Positive | 📉 4 Negative https://t.co/zHRzM36MVv Educational Purposes!
@UndercodeUpdate
6 Sept 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ ثغرة تجاوز مصادقة في نيت سكيلر تستغل فعلياً بعد نشر كود استغلال عام. المعرف : CVE-2026-19490 درجة الخطورة : 9.3 (CVSS v4.0) - Critical الإصدارات المتأثرة : NetScaler 14.1 and 13.1
@KasperskyDev
6 Sept 2026
304 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix NetScaler auth bypass (CVE-2026-19490) is under active exploitation and PaperCut RCE chain is hitting schools; patch both now. #CyberSecurity #BlueTeam https://t.co/wTIK1Z64Gv
@itsalreadywhen
5 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
22,000 Citrix NetScaler gateways exposed. Auth bypass. No credentials needed. CVE-2026-19490 (CVSS 9.3) is under active exploitation. Prior CVE-2026-8452 patch is insufficient. Patch to 14.1-73.32 now. https://t.co/RhXxGFfsqM #CyberSecurity #Citrix #NetScaler #ZeroDay #VPN ht
@DecryptionDigst
5 Sept 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Citrix NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) is being actively exploited in the wild. PaperCut NG/MF pre-auth RCE chain (CVE-2026-81578/82078) hit CISA KEV, targeting schools & universities. Patch immediately. #infosec #CVE #0day
@ita_ipo
5 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are targeting critical Citrix NetScaler flaw CVE-2026-19490, an auth bypass in ADC/Gateway, per Previdian. Check AAA virtual server configs and patch fast. #Citrix #CyberSecurity #ThreatIntel https://t.co/Fn3AP6bbsM
@CyberWorldOps
5 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-19490, CVSS 9.3, lets an unauthenticated attacker skip NetScaler's login through an alternate auth path, no creds needed. A credible PoC is circulating, exploitation already tracked. Third NetScaler CVE under active attack this month. Patch to 14.1-73.32 or 13.1-63.21. h
@SynScanNet
5 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
NetScalerの認証回避CVE-2026-19490に実環境での悪用試行 — 脆弱性情報のPrevidianがセンサーで観測、PoC公開の翌日から https://t.co/EIujU0PFc5
@NEXSIGHTNEWS
5 Sept 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NetScaler ADC & Gateway Critical Vulnerability (CVE-2026-19490, CVSS 9.3) Critical Vulnerability Alert! NetScaler ADC and NetScaler Gateway is affected by CVE-2026-19490. 🔍 Identify Targets via ZoomEye: Search Dork: app="NetScaler" Exposure: 116.6k instances identi
@zoomeyebot
5 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-19490: Η κρίσιμη ευπάθεια στο Citrix NetScaler https://t.co/Xt0cREF5V3
@SecNews_GR
5 Sept 2026
134 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ACSC is on Citrix NetScaler ADC and Gateway. CVE-2026-19489 memory overflow. CVE-2026-19490 auth bypass on gateway/SAML. Patches since 19 Aug. Patch now, or confirm your MSP did. https://t.co/b0vZAE592H
@JustinMiddler
5 Sept 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Citrix NetScaler authentication bypass (CVE-2026-19490) now actively exploited in the wild. Patch exposed appliances urgently. #Citrix #NetScaler #Exploit #CyberSecurity
@chris_uk2026
5 Sept 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Citrix NetScaler #CVE-2026-19490: Critical Authentication Bypass Under Active Exploitation — Patch Immediately + Video -Prediction: 📈 4 Positive | 📉 6 Negative https://t.co/IqqUeuCtXP Educational Purposes!
@UndercodeUpdate
5 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨🔐 CYBERSÉCURITÉ — Une vulnérabilité critique affectant Citrix NetScaler est désormais ciblée dans des attaques. La faille CVE-2026-19490 permet un contournement de l’authentification sur certaines configurations NetScaler ADC et Gateway, notamment les systèmes
@ActuX_off
4 Sept 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Just built a working PoC for CVE-2026-19490 from scratch — no public PoC existed for it, so I made one. 🛠️ https://t.co/29G6zd6n3e #CVE-2026-19490
@SaadFellahii
3 Sept 2026
75 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490) https://t.co/SqDo7Ler3J via @SystemTek_UK
@SystemTek_UK
2 Sept 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix NetScaler の脆弱性 CVE-2026-19490/19489 が FIXした:認証バイパスと DoS の恐れ https://t.co/3fKgbyGl03 NetScaler ADC/Gateway アプライアンスにおいて、認証判定処理およびメモリ制御の脆弱性 CVE-2026-19490/CVE-2026-19489
@iototsecnews
28 Aug 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Patch Now | August 26, 2026 Bringing these vulnerabilities to your attention. - Windows DHCP Client (CVE-2026-44815, CVSS 9.8) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3) - macOS Screen Sharing (CVE-2026-65400, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC
@CERT_UG
26 Aug 2026
76 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Patch Now | August 24, 2026 Bringing these CVEs to your attention! - Windows TFTP Server (CVE-2026-62893, CVSS 9.8 - SharePoint (CVE-2026-63520, CVSS 9.1) - Citrix NetScaler (CVE-2026-19490, CVSS 9.3): https://t.co/1d3yDRvnoU | #CyberSafeUG #CERTUGCC https://t.co/pZmfJBv
@CERT_UG
24 Aug 2026
226 Impressions
2 Retweets
4 Likes
0 Bookmarks
0 Replies
1 Quote
Citrixは、NetScalerの認証バイパスに関する重大な脆弱性(CVE-2026-19490)を修正するよう顧客に強く求めている Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) #HelpNetSecurity (Aug 21) https://t.co/e6qRt
@foxbook
24 Aug 2026
230 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 セキュリティトレンド (08:17 JST) ① ハッカーの「オフ会」発祥、世界最大セキュリティイベント「Black Hat」で注目された"AI暴走"の次に ... https://t.co/N0BBihWJZ9 ② Citrix、NetScalerの2脆弱性を修正 CVE-2026-19490はCV
@kenebeii
23 Aug 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix、NetScalerの2脆弱性を修正 CVE-2026-19490はCVSS 9.3、認証回避のおそれ https://t.co/0uTeWTQCJt #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
@securityLab_jp
23 Aug 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) - Help Net Security https://t.co/iJj9v0UDNu
@PVynckier
23 Aug 2026
110 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#Citrix has patched a critical authentication bypass #vulnerability in NetScaler ADC and Gateway. CVE-2026-19490 (CVSS 9.3) needs no credentials and no user interaction, only an appliance running Gateway, an AAA vserver or a SAML action: https://t.co/EjpVktBomB
@step9consulting
22 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Citrix NetScaler vulnerabilities CVE-2026-19490 & CVE-2026-19489 now pose major auth bypass and DoS risk. Whether you're using ADC, Gateway, or FIPS/NDcPP variants—exposed builds include 14.1-before-73.32 & 13.1-before-63.21. Check SAML actions, AAA vservers &a
@dailytechonx
22 Aug 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical NetScaler vulnerabilities patched. Cloud Software Group fixed two flaws affecting customer-managed NetScaler ADC and Gateway deployments: 🔴 CVE-2026-19490 (CVSS 9.3): Authentication bypass affecting certain Gateway and AAA configurations. 🟠 CVE-2026-19489 (CVS
@socradar
21 Aug 2026
361 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) - https://t.co/LxIVTIRxni - @rapid7 - #Citrix #NetScaler #Vulnerability #CVE #Cybersecurity #CyberSecurityNews #SecurityNews
@helpnetsecurity
21 Aug 2026
563 Impressions
1 Retweet
0 Likes
1 Bookmark
0 Replies
0 Quotes
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490): Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is… https://t.co/hfWOrqvVy8 htt
@shah_sheikh
21 Aug 2026
50 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Citrix flags urgent NetScaler patching for CVE-2026-19490 and CVE-2026-19489, which can enable auth bypass and denial of service on specific setups. CISA still tracks prior Citrix flaws in KEV. #Citrix #NetScaler #CISA https://t.co/wJ9oSlnWFy https://t.co/mNrBDWCFyx
@TweetThreatNews
20 Aug 2026
185 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NetScaler CVE-2026-19490: Critical auth bypass (CVSS 9.3) -- 22K+ exposed gateways with no workaround. https://t.co/2qyG9d1E2V #ThreatIntel #CVE_2026_19490 #CVE_2026_19489 #Web https://t.co/szqmRWGCF7
@threadlinqs
20 Aug 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-19489 Memory overflow vulnerability leading to unpredictable behavior or Denial of Service CVE-2026-19490 Authentication bypass using an alternate path NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://t.co/EiGLT9P3q1
@autumn_good_35
20 Aug 2026
428 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Upozorňujeme na dvě závažné zranitelnosti v Citrix NetScaler ADC a NetScaler Gateway, CVE-2026-19490 a CVE-2026-19489. Zranitelnost CVE-2026-19490 s hodnocením CVSS 9.3 umožňuje neautentizovanému útočníkovi obejít autentizaci v konfiguracích využívajících
@GOVCERT_CZ
20 Aug 2026
380 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cloud Software Group patched two critical flaws in NetScaler ADC and Gateway. CVE-2026-19490 enables authentication bypass on SSL VPN, ICA proxy, CVPN and RDP proxy configurations. CVE-2026-19489 triggers buffer overflow when SIP ALG is active in LSN groups. Fixed in 14.1-73.32
@WorldCyberNewsX
20 Aug 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NetScaler ADC/Gatewayに認証回避の重大欠陥 — CVSS 9.3のCVE-2026-19490など2件、Gateway/AAA構成が影響(CTX696939) https://t.co/0294GUkcLq
@NEXSIGHTNEWS
20 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Heat Radar|2026/08/20 05:00 JST 今回は①CVE-2026-19490 Citrix NetScale…の件、②CVE-2026-64849 CISA KEV追加の件、③Windows IKE Extension RCE悪用の件を中心に、ほか4件を含めて音声で7件扱います。
@cyberheatradar
19 Aug 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 #CRITICAL https://t.co/NU1Sp0Ev0q
@samilaiho
19 Aug 2026
854 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL SECURITY ALERT: Citrix disclosed CVE-2026-19489 & CVE-2026-19490 affecting NetScaler ADC and Gateway. Customers should upgrade to recommended builds ASAP. Need help? IntraSystems: 866.202.0020 https://t.co/uOIUEwI3kJ #CyberSecurity #Citrix #NetScaler
@Intra_Access
19 Aug 2026
111 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes