Critical Citrix NetScaler Flaw Lets Remote Attackers Bypass Authentication Without Credentials
Brief
Cloud Software Group has issued a critical security bulletin warning customers of two serious vulnerabilities affecting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).
Tracked as CVE-2026-19489 and CVE-2026-19490, the flaws could allow attackers to trigger denial-of-service conditions or bypass authentication entirely on unpatched appliances, putting enterprise remote access infrastructure at significant risk.
Critical Citrix NetScaler Vulnerability
The more severe of the two, CVE-2026-19490, carries a CVSS v4. 0 base score of 9. 3 and is classified under CWE-288, Authentication Bypass Using an Alternate Path. This flaw allows an attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server.
