---
schema: 1
kind: vulnerability
title: "CVE-2026-19490 — Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed"
headline: "The precondition is wider than the headline version numbers suggest — on older builds a Gateway or AAA vserver alone is enough"
summary: >
  Citrix published a bulletin on 2026-08-19 covering two NetScaler ADC and NetScaler Gateway flaws, relayed the
  same day by CERT-EU as advisory 2026-010. CVE-2026-19490 is an authentication bypass using an alternate path,
  scored 9.3, against appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA
  virtual server; CVE-2026-19489 is a memory overflow reachable only where SIP ALG is enabled on a Large Scale
  NAT group. The exposure boundary is the operationally important part: on 14.1-43.56 and 13.1-61.28 and later
  the bypass applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS any Gateway
  or AAA virtual server configuration is enough. Fixed in 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277. A public proof-of-concept appeared around 2026-09-03, exploitation attempts followed the same day, and CISA added the CVE to its KEV catalog on 2026-09-09.
discovered_at: "2026-08-20T04:33:00Z"
updated_at: "2026-09-08T04:47:00Z"
event_date: "2026-08-19"
run_id: 2026-08-20T0409Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, auth-bypass, pre-auth, patch-available, dos, actively-exploited, poc-public, cisa-kev]
regions: [global, europe]
sectors: [public-sector, energy, finance, healthcare, telco]
entities: []
techniques: [T1190]
affected_products: ["Citrix NetScaler ADC", "Citrix NetScaler Gateway"]
cves:
  - id: CVE-2026-19490
    cvss: "9.3"
    epss: 0.0337
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, poc-public, patch-available]
    affected: "14.1 before 14.1-73.32; 13.1 before 13.1-63.21; NetScaler ADC FIPS before 14.1-73.32 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.277"
    fixed: "14.1-73.32; 13.1-63.21; 14.1-73.32 FIPS; 13.1-37.277"
  - id: CVE-2026-19489
    cvss: "8.8"
    epss: 0.00388
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "14.1 before 14.1-73.32; 13.1 before 13.1-63.21; NetScaler ADC FIPS before 14.1-73.32 FIPS; NetScaler ADC FIPS and NDcPP before 13.1-37.277 — only where SIP ALG is enabled on a Large Scale NAT group"
    fixed: "14.1-73.32; 13.1-63.21; 14.1-73.32 FIPS; 13.1-37.277"
sources:
  - url: "https://cert.europa.eu/publications/security-advisories/2026-010/"
    publisher: "CERT-EU"
    date: "2026-08-19"
    role: primary
  - url: "https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/"
    publisher: "Rapid7"
    date: "2026-08-19"
    role: corroborating
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318"
    publisher: "NCSC-NL (Nationaal Cyber Security Centrum)"
    date: "2026-09-07"
    role: corroborating
  - url: "https://previdian.com/CVE-2026-19490"
    publisher: "Previdian (Ryan Dewhurst)"
    date: "2026-09-08"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/"
    publisher: "BleepingComputer, citing Previdian (Ryan Dewhurst)"
    date: "2026-09-04"
    role: corroborating
  - url: "https://fieldeffect.com/blog/early-exploitation-citrix-netscaler-vulnerability"
    publisher: "Field Effect Security Intelligence Team"
    date: "2026-09-04"
    role: corroborating
  - url: "https://api.first.org/data/v1/epss?cve=CVE-2026-19489"
    publisher: "FIRST.org (EPSS)"
    date: "2026-09-07"
    role: corroborating
  - url: "https://api.first.org/data/v1/epss?cve=CVE-2026-19490"
    publisher: "FIRST.org (EPSS)"
    date: "2026-09-09"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog (JSON feed)"
    date: "2026-09-09"
    role: corroborating
closed_sources: []
evidence:
  - quote: "The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path."
    publisher: "CERT-EU"
  - quote: "As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild."
    publisher: "Rapid7"
  - quote: "PoC code is available for CVE-2026-19490. NCSC considers it highly likely that abuse will occur in the short term. (translated from Dutch)"
    original: "Er is Proof of Concept code beschikbaar voor CVE-2026-19490. Het NCSC acht het zeer waarschijnlijk dat op korte termijn misbruik zal plaatsvinden."
    publisher: "NCSC-NL (Nationaal Cyber Security Centrum)"
    source_url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318"
  - quote: "On 3 September, one of our NetScaler sensors received requests matching the PoC from three distinct source IPs, geolocated to Australia, the United States and Germany."
    publisher: "BleepingComputer, citing Previdian (Ryan Dewhurst)"
    source_url: "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/"
verification: multi-source
sourcing_note: >
  Citrix's own bulletin CTX696939 is served from a support portal that renders client-side and could not be read
  directly as of 2026-08-20, so the vendor's determinations are cited through CERT-EU's advisory, which reproduces the
  scores, preconditions and affected builds, and through Rapid7's analysis, which independently supplies the
  CVSS v4.0 basis for the 9.3 score, the same affected and fixed build list, and its own exploitation
  observation. Neither source states an authentication requirement for CVE-2026-19489; this entry records it as
  pre-authentication because the SIP ALG path processes traffic traversing the NAT before any authentication
  step, which is this entry's assessment rather than a quoted claim.
confidence: high
references: [2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem]
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Inspect every NetScaler running configuration for `add authentication samlAction`, `add authentication vserver` or `add vpn vserver`, and patch any appliance that matches to 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS or 13.1-37.277 now — on builds older than 14.1-43.56 / 13.1-61.28 and on 13.1 FIPS, a Gateway or AAA virtual server alone is enough to be exposed, with no SAML action required. A public exploit is live and sensor telemetry confirms attempts against it; review authentication and session logs on every appliance that was internet-exposed and unpatched since 2026-09-03 for signs of a successful bypass before treating it as clean."
updates:
  - at: "2026-09-08T04:47:00Z"
    run_id: 2026-09-08T0411Z-intel
    type: update
    summary: >
      A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03, and
      vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching it
      from multiple source IPs within 24 hours, with continued activity through 2026-09-07.
      NCSC-NL updated its advisory the same day to state PoC code is public and that it assesses
      imminent widespread exploitation as highly likely. Status moves from patch-available-only
      to poc-public and exploited; EPSS scores are now recorded for both CVEs. Credibility moves
      from 2 to 1 given independent confirmation from a national CERT and a vulnerability-intelligence
      firm's own sensor telemetry.
    fields: [updated_at, cves, tags, actions, sources, evidence, classification, sourcing_note, body]
  - at: "2026-09-10T05:30:00Z"
    run_id: 2026-09-10T0410Z-intel
    type: correction
    summary: >
      The 2026-09-08 update stated CVE-2026-19490 had not been added to CISA's KEV catalog; CISA added it on
      2026-09-09 (due date 2026-09-12). This is a listing/bookkeeping addition — the CVE was already recorded
      as exploited before this listing — so no exploitation-status narrative changes; the stale sentence is
      corrected in place. Also added the missing FIRST.org EPSS citation for CVE-2026-19490 (score unchanged,
      0.0337, verified against FIRST.org); the entry's only prior EPSS source was scoped to CVE-2026-19489.
    fields: [cves, tags, body, sources]
  - at: "2026-09-13T14:50:00Z"
    run_id: 2026-09-13T1307Z-audit
    type: improvement
    internal: true
    summary: >
      The Previdian sensor-telemetry evidence quote records a live running counter that has since
      moved (18 attempts when quoted on 2026-09-08; 56 on 2026-09-13), so it could not be
      re-verified as a substring of the cited page. The quote is unchanged and was correct when
      taken; it now carries an as_of date and a note saying the source publishes no dated snapshot.
      Same class as the 2026-09-06 audit's finding on citing a live EPSS API URL for a historical
      value: a moving figure needs its as-of date attached or it reads as a falsified quote later.
    fields: [evidence]
  - at: "2026-09-29T21:57:49Z"
    run_id: 2026-09-29T2134Z-audit
    type: correction
    summary: >
      The summary still said Rapid7 reported no observed exploitation, which the 2026-09-08 and
      2026-09-10 records had overtaken: a public proof of concept appeared around 2026-09-03,
      exploitation attempts followed the same day, and CISA added the CVE to its KEV catalog on
      2026-09-09. The summary now says so. The evidence quotation of Previdian's live attempt counter
      is removed, since the page publishes a running total that can never be re-verified; the dated
      account of that telemetry in the analysis stays.
    fields: [evidence, summary]
migrated_from: null
---

Citrix published a security bulletin on 2026-08-19 covering two vulnerabilities in NetScaler ADC and NetScaler Gateway, and CERT-EU issued its own advisory for its constituency the same day, recommending that affected devices be updated as soon as possible ([CERT-EU, 2026-08-19](https://cert.europa.eu/publications/security-advisories/2026-010/)). The more serious of the two, CVE-2026-19490, is described as an authentication bypass using an alternate path and scored 9.3 ([CERT-EU, 2026-08-19](https://cert.europa.eu/publications/security-advisories/2026-010/)) — a CVSS v4.0 base score, per Rapid7's analysis of the same advisory ([Rapid7, 2026-08-19](https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/)). It applies where the appliance is configured as a Gateway — SSL VPN, ICA Proxy, CVPN or RDP Proxy — or as an AAA virtual server, which is the configuration that fronts remote access and authentication brokering for the network behind it.

The part that decides how much of an estate is exposed is version-dependent, and it cuts the wrong way for anyone behind on builds: on 14.1-43.56 or later and 13.1-61.28 or later the flaw applies only when a SAML action is configured, but on earlier builds and on 13.1 FIPS, a Gateway or AAA virtual server configuration is sufficient on its own ([CERT-EU, 2026-08-19](https://cert.europa.eu/publications/security-advisories/2026-010/)). An operator who checks only for SAML and concludes they are unaffected will be wrong on exactly the appliances that are furthest behind. The second flaw, CVE-2026-19489, is a memory overflow that can lead to unpredictable behaviour or denial of service, and it is reachable only where SIP ALG is enabled inside a Large Scale NAT group configuration ([CERT-EU, 2026-08-19](https://cert.europa.eu/publications/security-advisories/2026-010/)).

Detection here is thin by nature — an authentication bypass on an appliance leaves no failed-credential trail, because the point of it is that the credential step does not happen. The telemetry class that carries signal is the authentication and session record on the Gateway or AAA virtual server itself: a session established for a user identity with no preceding credential-validation or SAML assertion-processing event for that same session, and session establishment from addresses or client profiles that do not match the population that normally reaches the appliance. Because CVE-2026-19489 manifests as unpredictable behaviour or a service failure rather than as a login, an unexplained NetScaler restart or packet-engine fault on an appliance carrying an LSN group with SIP ALG belongs in the same review rather than in capacity triage. Fixed builds are 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS and 13.1-37.277 ([Rapid7, 2026-08-19](https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/)); where CVE-2026-19489 cannot be patched immediately, SIP ALG on LSN groups that do not need it is a configuration that can simply be turned off.

**Defender takeaway:** Rapid7's 2026-08-19 recommendation to patch on an emergency basis, reasoning that Citrix products are high-value targets that tend to see exploitation quickly after disclosure, is no longer a hedge — a public proof-of-concept has been live since 2026-09-03 and sensor telemetry confirms exploitation attempts against it (see the update below). That reasoning was never abstract for this constituency: this is the second NetScaler pre-authentication bypass affecting this constituency in five days, after the root chain published against the earlier June/July bulletin on 2026-08-15, and NetScaler Gateway is a common internet-facing remote-access layer in European government and critical-infrastructure networks.

## Update — 2026-09-08T04:47:00Z

A credible public proof-of-concept for CVE-2026-19490 went live around 2026-09-03 ([NCSC-NL, 2026-09-07](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318)). Vulnerability-intelligence firm Previdian recorded exploitation-attempt traffic matching that PoC from three distinct source IPs, geolocated to Australia, the United States and Germany, on 2026-09-03 ([BleepingComputer, citing Previdian, 2026-09-04](https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/)), and Previdian's own tracker, refreshed 2026-09-08, now records 18 exploitation attempts total from 9 unique attacker IPs across 5 countries (Australia, Germany, Japan, Taiwan and the United States) — up from the three-IP, three-country snapshot reported four days earlier — with sensor activity most recently observed 2026-09-07: evidence of exploitation attempts, though not confirmation of successful compromise ([Previdian, 2026-09-08](https://previdian.com/CVE-2026-19490)). Field Effect separately reported on the same activity and adds an operationally important precondition detail: on some newer builds the bypass additionally requires a configured SAML authentication action, while on older affected versions a Gateway or AAA virtual server configuration alone is enough — consistent with, and sharpening, this entry's own version-dependent exposure boundary above ([Field Effect Security Intelligence Team, 2026-09-04](https://fieldeffect.com/blog/early-exploitation-citrix-netscaler-vulnerability)). NCSC-NL updated its advisory on 2026-09-07 specifically to flag that PoC code is now public and that it assesses imminent widespread exploitation as highly likely (translated from Dutch) ([NCSC-NL, 2026-09-07](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0318)). CVE-2026-19490 had not been added to CISA's KEV catalog as of this update (see the correction below).

## Correction — 2026-09-10T05:30:00Z

CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a remediation due date of 2026-09-12 for federal civilian agencies. This CVE was already recorded here as exploited before this listing, so the addition is a jurisdiction-agnostic confirmation of what this entry already stated rather than a new exploitation-status development.

## Correction — 2026-09-29T21:57:49Z

The summary of this entry still said Rapid7 had observed no exploitation, the state on 2026-08-19. As the updates of 2026-09-08 and 2026-09-10 record, a public proof of concept appeared around 2026-09-03, exploitation attempts followed the same day, and CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog on 2026-09-09. The summary now reflects that.
