
In short: CVE-2026-19490 is a critical authentication bypass vulnerability affecting NetScaler ADC and Gateway. With a CVSS 9.3 score, it requires specific Gateway/AAA configurations. Fixed in versions 14.1-73.32 and 13.1-63.21. No active exploitation reported yet.
CVE-2026-19490 refers to an authentication bypass vulnerability in NetScaler ADC and Gateway. This flaw allows attackers to bypass authentication using alternate paths, an extremely risky scenario as it permits unauthorized access without proper validation.
The vulnerability predominantly affects devices configured as a Gateway (SSL VPN, ICA Proxy) or as an AAA virtual server. On newer builds, a specific SAML action configuration is required. However, older builds are susceptible with standard Gateway configurations.
SAML precondition is a critical factor in newer firmware, adding complexity to exploitability. Older firmware lacks this requirement, making those systems inherently more vulnerable without comprehensive SAML setups.
NetScaler ADC and Gateway versions 14.1-73.32 and 13.1-63.21 contain patches for this flaw. To confirm your build, use configuration check strings such as add authentication samlAction.
Firmware BranchVulnerable ConditionFixed Version14.1-43.56+Requires SAML action14.1-73.32 or later13.1-61.28+SAML or AAA configuration13.1-63.21 or later
As of the latest advisory by Citrix on 19 August 2026, there has been no sign of active exploitation. However, it remains crucial to patch due to the historical precedence of rapid exploitation following disclosure.
NetScaler vulnerabilities are quickly exploited due to their use in securing remote access—a prime target for attackers.
Conduct comprehensive infrastructure audits using tools like EASM. These measures help in locating and securing any inadvertently exposed gateways.
NetScaler products have previously been attractive targets for exploitation. The pattern of quick weaponisation necessitates a swift defensive stance—understanding historical breaches helps prepare timely countermeasures.
CVE-2026-19490 reveals the critical importance of maintaining up-to-date security for edge appliances. Regular vigilance and proactive management form the foundation of cybersecurity resilience, ensuring that your organization's external exposures are well-guarded against looming threats.
Unlock full visibility of your external attack surface with DarkInvader’s continuous, real-time monitoring. Create your free account to discover unknown assets, detect emerging risks and stay ahead of potential threats before attackers can exploit them.
Create My Free Account