Citrix NetScaler ADC and Gateway Authentication Bypass Vulnerability
- Severity
- HIGH
- Affected component
- citrix-netscaler-adc (other)
- Patched version
- Not yet available
An authentication bypass vulnerability in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-19490, is reportedly being exploited in the wild. Users of these products should assess their exposure and apply patches as they become available.
What happened
Citrix NetScaler ADC and NetScaler Gateway contain a critical authentication-bypass vulnerability, tracked as CVE-2026-19490. This vulnerability allows an unauthenticated remote threat actor to bypass authentication when the appliance is configured as an AAA virtual server or as a Gateway. The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that this flaw is being actively exploited in attacks.
The vulnerability impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. Citrix patched the flaw on August 19, 2026, but the exact version ranges affected have not been officially published yet.
Users should monitor their configurations and apply patches as they become available from Citrix. The primary sources, including CISA and SecurityWeek, should be consulted for the latest information and updates on this vulnerability.
What to do about it
- Monitor your Citrix NetScaler ADC and NetScaler Gateway configurations for any signs of exploitation.
- Apply patches from Citrix as soon as they become available.
- Consult the primary sources for the latest information and updates on this vulnerability.
- No official fix has been published yet for specific version ranges. Monitor the sources below for updates.
How 0Day would have caught this
citrix-netscaler-adc is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Citrix NetScaler ADC or NetScaler Gateway configured as an AAA virtual server or as a Gateway, you may be affected. The exact version ranges have not been officially published yet.
What should I do right now?
Monitor your configurations for any signs of exploitation and apply patches from Citrix as soon as they become available. Consult the primary sources for the latest information and updates.
Has this been exploited in the wild?
Yes, the vulnerability is reportedly being exploited in the wild.