CVE Tools
Back to feed
Patch released NetScaler ADC auth-bypass NetScaler Gateway Citrix network-edge

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Citrix has released security updates for NetScaler ADC and NetScaler Gateway to remediate two distinct vulnerabilities, the most severe being an authentication bypass tracked as CVE-2026-19490 with a CVSS score of 9.3. This critical flaw allows remote, unauthenticated attackers to circumvent access controls on gateways configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or AAA services without any user interaction. A second high-severity issue, CVE-2026-19489, involves a memory overflow in SIP ALG configurations that can result in denial-of-service conditions. Organizations should urgently apply the fixes available in NetScaler versions 14.1-73.32, 13.1-63.21, and other specified builds, as Rapid7 predicts imminent exploitation attempts given the widespread deployment of these appliances in enterprise perimeters.