Citrix NetScaler Auth Bypass CVE-2026-19490 Actively Exploited, Patches Available
Attackers are actively targeting a critical authentication bypass vulnerability, CVE-2026-19490, in Citrix NetScaler ADC and Gateway products, with attack attempts matching a public proof-of-concept observed from multiple regions. The flaw allows an unauthenticated remote attacker to bypass authentication on devices configured as Gateway or AAA virtual servers without any user interaction. Security firm Previdian confirmed that incoming requests to their sensors aligned with the known PoC exploit pattern. Affected versions span NetScaler ADC and Gateway 13.1 and 14.1 lines, with patched versions 14.1-73.32 and 13.1-63.21 now available for standard builds. Citrix has urged administrators to apply patches immediately and verify SAML and FIPS configurations against the official advisory CTX696939.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in