CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-08-20
HIGHCVE-2026-19490 +1exploitedupdatedNATOA1vulnerability

CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed

The precondition is wider than the headline version numbers suggest; on older builds a Gateway or AAA vserver alone is enough

Defender actions

  • Inspect every NetScaler running configuration for add authentication samlAction, add authentication vserver or add vpn vserver, and patch any appliance that matches to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS or 13.1-37.277 now, on builds older than 14.1-43.56 / 13.1-61.28 and on 13.1 FIPS, a Gateway or AAA virtual server alone is enough to be exposed, with no SAML action required. A public exploit is live and sensor telemetry confirms attempts against it; review authentication and session logs on every appliance that was internet-exposed and unpatched since 2026-09-03 for signs of a successful bypass before treating it as clean.

Analysis

Citrix published a security bulletin on 2026-08-19 covering two vulnerabilities in NetScaler ADC and NetScaler Gateway, and CERT-EU issued its own advisory for its constituency the same day, recommending that affected devices be updated as soon as possible (CERT-EU, 2026-08-19). The more serious of the two, CVE-2026-19490, is described as an authentication bypass using an alternate path and scored 9.3 (CERT-EU, 2026-08-19), a CVSS v4.0 base score, per Rapid7's analysis of the same advisory (Rapid7, 2026-08-19). It applies where the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN or RDP Proxy) or as an AAA virtual server, which is the configuration that fronts remote access and authentication brokering for the network behind it.

The part that decides how much of an estate is exposed is version-dependent, and it cuts the wrong way for anyone behind on builds: on 14.1-43.56 or later and 13.1-61.28 or later the flaw applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS, a Gateway or AAA virtual server configuration is sufficient on its own (CERT-EU, 2026-08-19). An operator who checks only for SAML and concludes they are unaffected will be wrong on exactly the appliances that are furthest behind. The second flaw, CVE-2026-19489, is a memory overflow that can lead to unpredictable behaviour or denial of service, and it is reachable only where SIP ALG is enabled inside a Large Scale NAT group configuration (CERT-EU, 2026-08-19).

Detection here is thin by nature; an authentication bypass on an appliance leaves no failed-credential trail, because the point of it is that the credential step does not happen. The telemetry class that carries signal is the authentication and session record on the Gateway or AAA virtual server itself: a session established for a user identity with no preceding credential-validation or SAML assertion-processing event for that same session, and session establishment from addresses or client profiles that do not match the population that normally reaches the appliance. Because CVE-2026-19489 manifests as unpredictable behaviour or a service failure rather than as a login, an unexplained NetScaler restart or packet-engine fault on an appliance carrying an LSN group with SIP ALG belongs in the same review rather than in capacity triage. Fixed builds are 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 (Rapid7, 2026-08-19); where CVE-2026-19489 cannot be patched immediately, SIP ALG on LSN groups that do not need it is a configuration that can simply be turned off.

Cited evidence

The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path.

CERT-EU 2026-08-19

As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.

Rapid7 2026-08-19

PoC code is available for CVE-2026-19490. NCSC considers it highly likely that abuse will occur in the short term. (translated from Dutch)

NCSC-NL (Nationaal Cyber Security Centrum) 2026-09-07

On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany.

BleepingComputer, citing Previdian (Ryan Dewhurst) 2026-09-04

Updates3

Update

A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03 (NCSC-NL, 2026-09-07). Vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching that PoC from three distinct source IPs, geolocated to Australia, the United States and Germany, on 2026-09-03 (BleepingComputer, citing Previdian, 2026-09-04), and Previdian's own tracker, refreshed 2026-09-08, now records 18 exploitation attempts total from 9 unique attacker IPs across 5 countries (Australia, Germany, Japan, Taiwan and the United States) (up from the three-IP, three-country snapshot reported four days earlier) with sensor activity most recently observed 2026-09-07: evidence of exploitation attempts, though not confirmation of successful compromise (Previdian, 2026-09-08). Field Effect separately reported on the same activity and adds an operationally important precondition detail: on some newer builds the bypass additionally requires a configured SAML authentication action, while on older affected versions a Gateway or AAA virtual server configuration alone is enough, consistent with, and sharpening, this entry's own version-dependent exposure boundary above (Field Effect Security Intelligence Team, 2026-09-04). NCSC-NL updated its advisory on 2026-09-07 specifically to flag that PoC code is now public and that it assesses imminent widespread exploitation as highly likely (translated from Dutch) (NCSC-NL, 2026-09-07). CVE-2026-19490 had not been added to CISA's KEV catalog as of this update (see the correction below).

Correction

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a remediation due date of 2026-09-12 for federal civilian agencies. This CVE was already recorded here as exploited before this listing, so the addition is a jurisdiction-agnostic confirmation of what this entry already stated rather than a new exploitation-status development.

Correction

The summary of this entry still said Rapid7 had observed no exploitation, the state on 2026-08-19. As the updates of 2026-09-08 and 2026-09-10 record, a public proof of concept appeared around 2026-09-03, exploitation attempts followed the same day, and CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09. The summary now reflects that.

Sources9

Revision history

  1. Published 2026-08-20T0409Z-intel
  2. Update 2026-09-08T0411Z-intel

    A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03, and vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching it from multiple source IPs within 24 hours, with continued activity through 2026-09-07. NCSC-NL updated its advisory the same day to state PoC code is public and that it assesses imminent widespread exploitation as highly likely. Status moves from patch-available-only to poc-public and exploited; EPSS scores are now recorded for both CVEs. Credibility moves from 2 to 1 given independent confirmation from a national CERT and a vulnerability-intelligence firm's own sensor telemetry.

    Changed: updated_at cves tags actions sources evidence classification sourcing_note body

  3. Correction 2026-09-10T0410Z-intel

    The 2026-09-08 update stated CVE-2026-19490 had not been added to CISA's KEV catalog; CISA added it on 2026-09-09 (due date 2026-09-12). This is a listing/bookkeeping addition (the CVE was already recorded as exploited before this listing) so no exploitation-status narrative changes; the stale sentence is corrected in place. Also added the missing FIRST.org EPSS citation for CVE-2026-19490 (score unchanged, 0.0337, verified against FIRST.org); the entry's only prior EPSS source was scoped to CVE-2026-19489.

    Changed: cves tags body sources

  4. Correction 2026-09-29T2134Z-audit

    The summary still said Rapid7 reported no observed exploitation, which the 2026-09-08 and 2026-09-10 records had overtaken: a public proof of concept appeared around 2026-09-03, exploitation attempts followed the same day, and CISA added the CVE to its KEV catalog on 2026-09-09. The summary now says so. The evidence quotation of Previdian's live attempt counter is removed, since the page publishes a running total that can never be re-verified; the dated account of that telemetry in the analysis stays.

    Changed: evidence summary

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.