Executive Summary
Citrix NetScaler ADC and NetScaler Gateway contain a critical authentication-bypass vulnerability, CVE-2026-19490, that allows an unauthenticated remote attacker to bypass authentication when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. Cloud Software Group (Citrix) disclosed the flaw on August 19, 2026 in security bulletin CTX696939, rating it CVSS v4.0 base 9.3 (CWE-288: Authentication Bypass Using an Alternate Path or Channel). NVD rates the same issue CVSS v3.1 9.8 and lists status Analyzed.
On September 9, 2026, CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation, with a federal remediation due date of September 12, 2026. The KEV record flags forensic triage required under BOD 26-04 as Yes; known ransomware campaign use remains Unknown. Security researchers and industry reporting cite exploitation in the wild from at least September 3, 2026. Organizations running customer-managed NetScaler ADC/Gateway on vulnerable builds with internet-facing Gateway or AAA configurations should treat this as an emergency patch-and-triage event, not routine CVE hygiene.
Technical Information
CVE-2026-19490 is an authentication bypass using an alternate path or channel (CWE-288). Per Citrix CTX696939, an unauthenticated remote threat actor may bypass authentication on affected NetScaler ADC and NetScaler Gateway appliances when those appliances are configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Secure Private Access Hybrid deployments that use NetScaler instances are also in scope per the vendor. The bulletin applies to customer-managed NetScaler ADC/Gateway; Cloud Software Group states it upgrades Citrix-managed cloud services and Citrix-managed Adaptive Authentication separately.
The attack is network-based, requires no privileges or user interaction, and is assessed as low complexity. NVD SSVC fields attributed to the CISA Coordinator characterize exploitation as active, automatable as yes, and technical impact as total.
Vendor-documented preconditions vary by build:
- On newer builds (for example, 14.1-43.56 or later, and 13.1-61.28 or later), exposure typically requires a SAML action configured in addition to Gateway/AAA.
- On earlier builds within the affected ranges—and for 13.1 FIPS—Gateway or AAA configuration alone is sufficient.
Citrix provides configuration check patterns operators can use to identify in-scope appliances, including:
add authentication samlAction .*add authentication vserver .*add vpn vserver .*
The same Citrix bulletin also covers companion CVE-2026-19489 (memory overflow / DoS-oriented, CVSS v4.0 8.8, SIP ALG on LSN group precondition), which is outside the KEV focus of this write-up but relevant for operators applying the same bulletin.
Credit for discovery: Samarth Vashisht, JPMorgan Chase penetration-test team (per Citrix CTX696939).
Affected Product Versions
Affected builds (vendor, August 19, 2026 — Citrix CTX696939):
- NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
- NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
- NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
- NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
Fixed versions (vendor):
- 14.1-73.32 and later
- 13.1-63.21 and later
- 14.1-FIPS 14.1-73.32 FIPS and later
- 13.1-FIPS and 13.1-NDcPP 13.1-37.277 and later
Prefer the Citrix CTX696939 fixed-build matrix over secondary summaries when closing residual risk.
Exploitation in the Wild
Timeline of public reporting:
- August 19, 2026 — Citrix publishes CTX696939. Rapid7’s initial Emerging Threat Response notes a critical unauthenticated remote authentication bypass and reports no observed exploitation at that time, while urging emergency patching given NetScaler’s perimeter role.
- Approximately September 2, 2026 — Industry reporting (SecurityWeek citing Previdian) states a public exploit appeared on GitHub; this advisory does not retrieve or reproduce exploit code.
- On or after September 3, 2026 — SecurityWeek reports exploitation claimed in the wild, citing Previdian sensor hits from multiple IPs and countries.
- September 9, 2026 — CISA adds CVE-2026-19490 to the KEV catalog among four new additions, establishing a September 12, 2026 federal due date and requiring forensic triage under BOD 26-04.
- September 10–11, 2026 — NVD lastModified reflects Analyzed status with KEV fields mirrored; Rapid7 updates its ETR to reference CISA KEV and active exploitation.
CISA’s KEV short description states that when configured as an AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. No official IoC list accompanies the KEV entry or the Citrix bulletin in the sources used here.
Threat Actor Profile
Neither Citrix, CISA, nor the primary technical sources reviewed for this advisory publicly attribute CVE-2026-19490 exploitation to a named advanced persistent threat (APT) group. CISA’s KEV addition confirms evidence of active exploitation but does not publish actor attribution, sector targeting, or ransomware linkage (known ransomware campaign use: Unknown). Reporting summarized by SecurityWeek, citing Previdian / Ryan Dewhurst sensor observations, describes opportunistic scanning and exploitation rather than a named, sector-specific campaign. Organizations should assume internet-exposed, unpatched Gateway/AAA instances are attractive targets for any actor capable of leveraging publicly discussed exploit techniques, without relying on unverified attribution.
Victimology and Targeting
Primary sources do not publish a sector- or geography-specific victim list for CVE-2026-19490. Risk concentrates on organizations and third parties that operate internet-facing, customer-managed NetScaler ADC/Gateway appliances in Gateway or AAA roles—especially SSL VPN, ICA Proxy, CVPN, and RDP Proxy terminations used for remote workforce, partner, or managed-service access. Because the bypass is unauthenticated on in-scope configurations and CISA assesses exploitation as active and automatable with total technical impact, any publicly reachable vulnerable Gateway/AAA instance should be treated as high priority for both remediation and pre-patch compromise assessment.
Workaround and Mitigation
Immediate actions:
- Inventory all customer-managed NetScaler ADC and NetScaler Gateway instances (including Secure Private Access Hybrid NetScaler instances) that terminate Gateway or AAA services, including those reachable from the internet or from untrusted networks.
- Upgrade to a vendor-fixed build: 14.1-73.32+, 13.1-63.21+, 14.1-73.32 FIPS+, or 13.1-37.277 (FIPS/NDcPP) as applicable.
- Use vendor configuration checks (samlAction / authentication vserver / vpn vserver) to confirm whether Gateway/AAA and SAML preconditions apply to each appliance’s build lineage.
- Because CISA KEV requires forensic triage (Yes) under BOD 26-04, do not treat “patched” as residual-risk closed until triage for the exposure window is complete. Follow CISA’s BOD 26-04 implementation / forensics triage guidance for exposed assets rather than inventing appliance-specific forensic playbooks not published by Citrix or CISA.
- Restrict management and Gateway/AAA exposure to trusted networks where operationally feasible; review authentication, session, and administrative logs for anomalous activity in the period before patching—especially around and after early September 2026 when public exploitation reporting began.
- Federal civilian executive branch agencies were subject to the September 12, 2026 KEV due date; other organizations should treat that date as a strong urgency signal even where BOD 26-04 is not binding.
- After patching: terminate suspicious sessions where warranted and rotate credentials or tokens that may have been exposed during the vulnerable window.
Unsupported installations should be migrated to supported software branches. For Citrix-managed cloud services, Cloud Software Group states patches are applied on the vendor side separately from customer-managed appliances.
Indicators of Compromise
Indicators of compromise are point-in-time and should be validated before enforcement. Official Citrix CTX696939 and CISA KEV materials reviewed for this advisory do not publish an authoritative IoC list or MITRE ATT&CK mapping for CVE-2026-19490; this advisory therefore does not invent IoCs or TTPs.
Operators should prioritize log review for anomalous unauthenticated or unexpected Gateway/AAA access around and after early September 2026, preserve pre-patch authentication and access logs for forensic triage, and treat “no public IoCs” as a reason for deeper session/log analysis—not as proof of non-compromise.
References
- Citrix / Cloud Software Group: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 (CTX696939), 2026-08-19 — https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog, 2026-09-09 — https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog
- CISA Known Exploited Vulnerabilities Catalog / KEV JSON feed — https://www.cisa.gov/known-exploited-vulnerabilities-catalog ; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk — https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance (forensics triage) — https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- NVD: CVE-2026-19490 — https://nvd.nist.gov/vuln/detail/CVE-2026-19490
- CVE Record: CVE-2026-19490 — https://www.cve.org/CVERecord?id=CVE-2026-19490
- Rapid7 ETR: CVE-2026-19490 Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway (published 2026-08-19, updated 2026-09-11) — https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/
- SecurityWeek: Critical NetScaler Vulnerability Exploited in Attacks, 2026-09-10 — https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/
- Cloud Software Group Trust Center / vulnerability reporting — https://www.cloud.com/trust-center/support
Third-Party Risk Bridge: Unpatched NetScaler Gateway Into Your Environment
Internet-facing NetScaler Gateway and AAA appliances are third-party remote-access chokepoints: they terminate SSL VPN, ICA Proxy, CVPN, and RDP Proxy for MSPs, IT support partners, and contractors who broker access into customer environments. CVE-2026-19490 is an unauthenticated authentication bypass on exactly those configurations. CISA’s September 9, 2026 KEV listing sets forensic triage required = Yes under BOD 26-04 (due September 12, 2026)—so a supplier’s “we patched” answer is incomplete without evidence they checked for pre-patch compromise on internet-facing Gateway/AAA. Any vendor still on builds before 14.1-73.32 / 13.1-63.21 / FIPS equivalents with public Gateway or AAA presents immediate third-party access risk into your environment, not theoretical CVE hygiene.
Ask suppliers now: (1) NetScaler ADC/Gateway version strings for every internet-facing Gateway/AAA instance used to reach you; (2) confirmation they meet Citrix CTX696939 fixed builds and whether SAML/Gateway preconditions applied; (3) forensic-triage evidence for the exposure window before patch (or before 2026-09-12, whichever later), aligned with CISA BOD 26-04—not patch confirmation alone.
Book a demo to see how Rescana tracks which vendors sit on KEV-vulnerable remote-access chokepoints like NetScaler Gateway/AAA, and whether “patched” is backed by triage evidence before residual third-party access risk is closed.
Forward this advisory to your TPRM owner if NetScaler Gateway, AAA, or a supplier VPN path terminates into your environment—they own the version, config-precondition, and forensic-triage asks above.



