CVE-2026-19490 is an authentication bypass vulnerability affecting certain customer-managed NetScaler ADC and NetScaler Gateway appliances. An unauthenticated remote attacker may be able to bypass authentication when an affected appliance is configured as a Gateway or AAA virtual server and meets the applicable build-specific conditions. The vulnerability is rated Critical (CVSS 3.x score of 9.8). CISA added it to its Known Exploited Vulnerabilities catalog on September 9, 2026.
Citrix classifies the flaw as an authentication bypass using an alternate path or channel (CWE-288). The affected appliance must be configured as a Gateway supporting SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. The additional SAML requirement varies by build:
These conditions apply to builds below the fixed versions listed below. The vulnerability can be reached over a network without prior privileges or user interaction. Citrix’s bulletin does not describe the exploit mechanism beyond its authentication bypass classification, so teams should not assume a particular request path or post-bypass level of access.

A NodeZero Rapid Response test has been developed to safely validate whether this authentication bypass can be exploited in your environment. The test uses real attack techniques to give teams evidence of exposure.
CISA also calls for forensic triage for this KEV entry. Retesting a patched appliance verifies the fix; it does not determine whether the appliance was compromised before patching.
Citrix identifies the following customer-managed builds as affected, subject to the applicable configuration preconditions:
Secure Private Access Hybrid deployments using customer-managed NetScaler instances are also in scope.
Upgrade to the fixed build for the appliance’s release train:
Citrix lists no workaround in its bulletin. The bulletin applies to customer-managed appliances; Cloud Software Group states that it updates Citrix-managed cloud services and Citrix-managed Adaptive Authentication.