Junglewise Threat Intelligence

CVE-2026-19490: Citrix NetScaler authentication bypass via alternate path

CVE-2026-19490 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-09-09

Executive brief

Citrix NetScaler is a critical networking appliance used by enterprises to manage user authentication and provide secure remote access through VPN and proxy services. This vulnerability allows attackers to completely bypass authentication and gain unauthorized access to protected applications and networks without valid credentials, potentially exposing sensitive business systems and data to compromise.

Technical details

The vulnerability is an authentication bypass flaw in Citrix NetScaler ADC and NetScaler Gateway that affects systems configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). The vulnerability exists due to improper handling of an alternate authentication path or channel, allowing unauthenticated remote attackers to bypass the authentication mechanism without valid credentials. The attack is network-accessible and requires no prior authentication or user interaction. Successful exploitation grants unauthorized access to gateway functionality and protected resources. The vulnerability has been observed exploited in the wild, indicating active threat actor activity. Patched versions and mitigation guidance from Citrix should be applied immediately.

Affected products

  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway

Timeline

  • 2026-09-09: disclosed
  • exploited: Observed exploited in wild

Related threats