CISA added a critical NetScaler authentication bypass to its exploited-vulnerability catalog on September 9, giving US federal agencies until September 12 to act. Customer-managed NetScaler Gateway and AAA virtual-server deployments are affected when their versions and configurations meet Citrix’s published conditions.
Citrix first disclosed CVE-2026-19490 on August 19. The issue is newly urgent because CISA now lists it as known exploited, although neither source identifies an attacker, victim, exploit path, or number of compromised organizations.
Exploitation forces immediate upgrades
Citrix describes CVE-2026-19490 as an authentication bypass using an alternate path and assigns it a CVSS 4.0 base score of 9.3. An unauthenticated remote attacker may bypass authentication when a vulnerable appliance is configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.
The vendor does not explain the alternate path. It also publishes no indicators of compromise, exploit-request signature, log pattern, or evidence tying the activity to ransomware. CISA records ransomware use as unknown.
Affected appliances require an upgrade. Citrix says, “Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.” Its bulletin lists no workaround or mitigating factor.
Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already received the necessary updates. The bulletin applies to customer-managed appliances, including NetScaler instances used in Secure Private Access Hybrid deployments.
Configurations that expose NetScaler appliances
Exposure is broader on older builds. NetScaler 14.1-43.55 and earlier, NetScaler 13.1-61.27 and earlier, and the listed 13.1 FIPS builds meet the vulnerability precondition when they run a Gateway or AAA virtual server.
Later affected builds add a SAML condition. NetScaler 14.1-43.56 or later, 14.1-66.68-FIPS or later, and 13.1-61.28 or later are in scope when a SAML action is configured alongside the relevant Gateway or AAA service. These bands remain affected only until their branch’s fixed floor.
The configuration export provides the fastest exposure split. Citrix tells administrators to inspect it for add authentication samlAction.*, add authentication vserver .*, and add vpn vserver .*. Those strings establish configuration state. They do not establish compromise.

Figure details
The figure compares older and later affected NetScaler builds. Older listed builds enter the exposed state when a Gateway or AAA virtual server is configured. Later listed builds require that service plus a SAML action. Both paths lead to the same required response: install the branch-specific fixed build, because Citrix lists no workaround. A separate note explains that Citrix-managed cloud services were already updated and are outside the customer-managed bulletin scope.
Citrix credits Samarth Vashisht of JPMorgan Chase’s penetration-testing team for reporting the vulnerabilities. The bulletin does not give a researcher-assigned name for the bypass.
Verify fixed builds and scope
Upgrade NetScaler ADC and Gateway 14.1 to 14.1-73.32 or later, and 13.1 to 13.1-63.21 or later. For FIPS appliances, the fixed floors are 14.1-73.32 FIPS and 13.1-37.277 FIPS; the latter also covers the 13.1 NDcPP branch.
Inventory customer-managed Gateway and AAA deployments before treating a later build as out of scope. Export the running configuration, identify the three published patterns, and map each appliance to its precise version band. On an older affected build, a Gateway or AAA match is enough to require the fix. On a later affected build, confirm whether a SAML action is also present.
Patch every in-scope appliance to its branch-specific fixed floor. Because CISA records active exploitation and Citrix supplies no compromise indicators, exposure remediation and incident assessment are separate jobs. The absence of the three configuration patterns can narrow exposure under the published conditions; it cannot prove that an appliance was never targeted.
Verify the result from the appliance itself. The expected outcome is a fixed-or-later build on every customer-managed Gateway or AAA appliance, with the configuration export retained to show which published preconditions applied before the upgrade. Upgrade any appliance still below its fixed floor; Citrix provides no compensating workaround.
