HomeSecurityCitrix NetScaler: Critical Authentication Bypass Vulnerability

Citrix NetScaler: Critical Authentication Bypass Vulnerability

Citrix has disclosed a critical authentication bypass vulnerability Citrixaffecting NetScaler ADC and NetScaler Gateway products , with the identifier CVE -2026-19490 . The vulnerability is rated with a CVSS v4.0 score of 9.3 , making it one of the most severe vulnerabilities disclosed for the platform this year. While there is no evidence of active exploitation yet, experts warn that an attack is likely to follow soon, given the critical position that NetScaler appliances occupy in corporate infrastructures.

Citrix NetScaler critical authentication bypass vulnerability CVE-2026-19490

CVE -2026-19490 can be exploited remotely by an unauthenticated attacker over a network , without requiring user interaction or elevated privileges . This means that a malicious actor could completely bypass authentication mechanisms and gain access to internal applications, credentials, and authenticated sessions. NetScaler ADC provides application delivery, traffic management, SSL/TLS offloading , and application security, while NetScaler Gateway offers secure remote access and VPN functionality .

Citrix notes that Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerability. This significantly broadens the impact beyond traditional VPN and gateway use cases to include identity and remote access infrastructures. Customers are urged to immediately upgrade their NetScaler instances to the recommended versions.

See also: Citrix NetScaler: Critical vulnerability exposes data

CVE-2026-19490: Technical details of the NetScaler vulnerability

According to Rapid7 and the Finnish National Cybersecurity Center (NCSC-FI), the affected versions include: NetScaler ADC and Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS. The range of affected versions is extremely wide, increasing the number of organizations worldwide at risk.

The vulnerability particularly affects systems using AAA virtual servers, ICA Proxy, CVPN, RDP Proxy. These configurations are particularly vulnerable because they are exposed to the Internet and are the first point of contact for remote users. Bypassing authentication at these points can lead to a complete breach of the corporate infrastructure, as the attacker gains access to internal systems without having to bypass additional security mechanisms.

Citrix NetScaler: Critical Authentication Bypass Vulnerability

NetScaler Vulnerability History in 2026: A Worrying Trend

CVE -2026-19490 is not the only serious vulnerability to be disclosed in NetScaler this year. In August 2026 , CVE-2026-8451 was also disclosed , a memory overread flaw in the SAML XML parser that can expose arbitrary process memory, including tokens and credentials, on devices configured as a SAML Identity Provider . Meanwhile, CVE-2026-8452 was described as a pre-authentication SAML heap overflow in the nsppe packet processing engine , triggered by crafted SAML responses and could lead to code execution as root by an unauthenticated user.

In July 2026, CVE-2026-13474, a denial-of-service related to the HTTP/2 in NetScaler ADC and Gateway. The pattern of these vulnerabilities reveals a worrying trend: the NetScaler repeatedly faces serious security issues related to authentication, SAML , and packet processing. These issues have repeatedly led to credential theft, session hijacking, or remote code execution.

See also: Citrix patches vulnerabilities in NetScaler ADC and Gateway

Why NetScaler is a high-value target for hackers

NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products that are typically deployed at or near the network perimeter. Their central position in an enterprise’s security infrastructure makes them highly attractive targets for malicious actors. An attacker who can bypass authentication on NetScaler essentially gains access to the “key” to the enterprise infrastructure, as they can reach internal applications, SSO systems, and application delivery infrastructures.

Rapid7 emphasizes that Citrix products are high-value targets that tend to be quickly attacked in practice once the details of a vulnerability become known. The company recommends that organizations prioritize patching. Historically, vulnerabilities in Citrix products have been rapidly exploited by ransomware groups and state actors, making immediate response absolutely necessary.

CVE-2026-55040 critical vulnerability Microsoft SharePoint authentication bypass PoC

According to SecurityWeek , Rapid7 has not identified any evidence of active exploitation, however the company expects malicious actors to soon exploit the critical flaw, given that NetScaler appliances are typically deployed in corporate DMZs and are publicly accessible.

See also: CISA: Citrix NetScaler vulnerability in KEV Catalog

Security Guide: How to Secure Your NetScaler

Citrix to specific versions. Organizations should upgrade their systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

After applying the patches, organizations should review logs for unusual authentication activity, strange sessions, and unexpected configuration changes. Authentication bypass vulnerabilities are often followed by credential theft or session abuse. Additionally, it is recommended to limit administrative access to trusted networks only and enable monitoring to detect suspicious activity in real time.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS