Critical Citrix NetScaler Authentication Bypass Targeted in Attacks
A critical authentication bypass vulnerability, tracked as CVE-2026-19490, affecting NetScaler ADC and NetScaler Gateway is being targeted by threat actors following the publication of public proof-of-concept exploit code. The vulnerability carries a CVSS v4.0 score of 9.3 (Critical) and is classified as CWE-288 – Authentication Bypass Using an Alternate Path or Channel. Successful exploitation could allow an unauthenticated remote attacker to bypass authentication controls on vulnerable NetScaler appliances configured as a Gateway, including SSL VPN, ICA Proxy, CVPN and RDP Proxy, or as an AAA virtual server. Exploitability depends on the affected NetScaler software version and, for certain releases, whether SAML authentication actions are configured.
The vulnerability poses a significant risk because NetScaler ADC and Gateway appliances are frequently positioned at the network perimeter and provide remote access and authentication services for business-critical applications. An attacker capable of bypassing these authentication controls could potentially obtain unauthorized access to applications and internal resources protected by the affected appliance. Citrix disclosed and released security updates for CVE-2026-19490 on 19 August 2026, strongly recommending that organizations running affected customer-managed NetScaler deployments upgrade to the appropriate fixed versions as soon as possible. There are currently no vendor-provided workarounds or mitigating factors, making patching the primary remediation measure.
The exploitation risk increased following the publication of a credible public proof-of-concept on 2 September 2026. Vulnerability intelligence provider Previdian subsequently detected requests matching the PoC against its NetScaler sensor infrastructure beginning on 3 September 2026. As of 5 September, Previdian reported 10 exploitation attempts originating from six unique IP addresses across Australia, Germany, Japan and the United States. However, these observations demonstrate exploitation attempts against monitoring infrastructure and do not currently confirm successful compromise of real-world organizations. The current EPSS probability is approximately 3.4%, further supporting prioritization of remediation for exposed and vulnerable NetScaler systems.
Attack Surface
Infrastructure
Tactics
Initial Access
Techniques
- T1190 – Exploit Public-Facing Application
SuperPRO's Threat Countermeasures Procedures
- Immediately upgrade affected NetScaler ADC and NetScaler Gateway appliances to the vendor-recommended fixed versions, including 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, or 13.1-37.277 FIPS/NDcPP as applicable. Where possible, upgrade to the latest supported release rather than only the minimum fixed build.
- Identify whether deployed NetScaler appliances meet the vulnerability preconditions, particularly systems configured as Gateway services such as SSL VPN, ICA Proxy, CVPN or RDP Proxy, or as AAA virtual servers. Organizations should also determine whether SAML authentication actions are configured on affected releases.
- Prioritize internet-facing NetScaler appliances for immediate remediation, as externally accessible Gateway and authentication services present the greatest opportunity for unauthenticated exploitation.
- Review NetScaler authentication, Gateway, AAA and SAML logs for abnormal or unauthorized authentication activity, particularly events occurring from 2 September 2026 onward, following publication of public proof-of-concept exploit code.
- Investigate unexpected authenticated sessions or access to applications protected by NetScaler, including unusual source IP addresses, abnormal user accounts, geographic anomalies, or sessions occurring without corresponding legitimate authentication events.
- Restrict access to NetScaler management interfaces to dedicated administrative networks, VPN connections, jump hosts or explicitly authorized source IP addresses. Management services should not be directly exposed to the public internet.
- Do not rely solely on WAF or perimeter filtering as remediation, because Citrix currently lists no official workaround or mitigating factor for CVE-2026-19490. Applying the vendor security update remains the primary corrective action.