CVE-2026-19490 | Citrix NetScaler ADC and NetScaler Gateway Authentication Bypass Vulnerability
Unauthenticated attackers can bypass Citrix NetScaler Gateway or AAA authentication via KEV-listed CVE-2026-19490.
CVE-2026-19490 is a critical (CVSS 9.8) authentication bypass (CWE-288) in customer-managed Citrix NetScaler ADC and Gateway appliances configured as a Gateway or AAA virtual server. Some builds also require a configured SAML action, and Citrix lists no workaround. Fixed builds include 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-37.277. Citrix disclosed it on August 19, 2026, CISA added it to the KEV catalog on September 9 requiring forensic triage, and Horizon3.ai published a NodeZero exposure test on September 28.