ctipilot.ch

Citrix NetScaler ADC/Gateway — authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19.

cve · CVE-2026-19490

Coverage timeline
1
first 2026-08-20 → last 2026-08-20
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Related entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Citrix NetScaler ADCCitrix NetScaler Gateway

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-20/cve-2026-19490-netscaler-gateway-aaa-auth-bypass · ATT&CK page ↗

Story timeline

  1. 2026-08-20CVE-2026-19490 — Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed
    trending-vulnerabilitiesThe precondition is wider than the headline version numbers suggest — on older builds a Gateway or AAA vserver alone is enough

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cert.europa.eu1 (50%)
  • rapid7.com1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Citrix NetScaler ADC/Gateway — authentication bypass using an alternate path on Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual servers; CVSS v4.0 9.3, no exploitation observed as of 2026-08-19. (1)

2026-08-20 · view entry permalink →

CVE-2026-19490 — Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed

Citrix published a security bulletin on 2026-08-19 covering two vulnerabilities in NetScaler ADC and NetScaler Gateway, and CERT-EU issued its own advisory for its constituency the same day, recommending that affected devices be updated as soon as possible (CERT-EU, 2026-08-19). The more serious of the two, CVE-2026-19490, is described as an authentication bypass using an alternate path and scored 9.3 (CERT-EU, 2026-08-19) — a CVSS v4.0 base score, per Rapid7's analysis of the same advisory (Rapid7, 2026-08-19). It applies where the appliance is configured as a Gateway — SSL VPN, ICA Proxy, CVPN or RDP Proxy — or as an AAA virtual server, which is the configuration that fronts remote access and authentication brokering for the network behind it.

The part that decides how much of an estate is exposed is version-dependent, and it cuts the wrong way for anyone behind on builds: on 14.1-43.56 or later and 13.1-61.28 or later the flaw applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS, a Gateway or AAA virtual server configuration is sufficient on its own (CERT-EU, 2026-08-19). An operator who checks only for SAML and concludes they are unaffected will be wrong on exactly the appliances that are furthest behind. The second flaw, CVE-2026-19489, is a memory overflow that can lead to unpredictable behaviour or denial of service, and it is reachable only where SIP ALG is enabled inside a Large Scale NAT group configuration (CERT-EU, 2026-08-19).

Detection here is thin by nature — an authentication bypass on an appliance leaves no failed-credential trail, because the point of it is that the credential step does not happen. The telemetry class that carries signal is the authentication and session record on the Gateway or AAA virtual server itself: a session established for a user identity with no preceding credential-validation or SAML assertion-processing event for that same session, and session establishment from addresses or client profiles that do not match the population that normally reaches the appliance. Because CVE-2026-19489 manifests as unpredictable behaviour or a service failure rather than as a login, an unexplained NetScaler restart or packet-engine fault on an appliance carrying an LSN group with SIP ALG belongs in the same review rather than in capacity triage. Fixed builds are 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 (Rapid7, 2026-08-19); where CVE-2026-19489 cannot be patched immediately, SIP ALG on LSN groups that do not need it is a configuration that can simply be turned off.

The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path.

CERT-EU 2026-08-19

As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.

Rapid7 2026-08-19

Builds on: 2026-08-15/netscaler-saml-signedinfo-overflow-preauth-root-rce-not-dos

vulnerability20 Aug 04:33Zmulti-sourceOpen finding ↗
Sources: CERT-EU · Rapid7