CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
CISA adds exploited Citrix NetScaler authentication bypass CVE-2026-19490 to the KEV catalog; federal agencies must patch by September 12.
CISA added CVE-2026-19490, a CWE-288 authentication bypass affecting NetScaler ADC and Gateway deployments configured as AAA virtual servers or Gateway services (including SSL VPN, ICA Proxy, and RDP Proxy), to the Known Exploited Vulnerabilities catalog. Citrix released fixes on August 19, 2026; honeypots recorded 56 attack attempts between September 3 and 8 after a public PoC, though no confirmed production compromises have been reported. Affected builds include 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21; newer installations require SAML IdP configuration to be exposed.
- CVE-2026-19490 lets unauthenticated attackers bypass login on NetScaler AAA virtual servers and Gateway configurations.
- Exploitation observed in honeypots (56 attempts September 3-8) after public PoC; no confirmed compromises yet.
- Fixes ship in 14.1-73.32 and 13.1-63.21; CISA KEV deadline September 12 with mandatory forensic triage.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19490 | Remote Authentication Bypass in Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability (CWE-288, 'using an alternate path or channel') that an unauthenticated remote threat actor can exploit. The flaw is triggerable when the appliance is configured as an AAA virtual server or as a Gateway, including SSL VPN, ICA Proxy, CVPN, or RDP Proxy deployments, allowing the attacker to bypass authentication without valid credentials. A successful bypass could give an attacker access to VPN-protected or AAA-gated resources as an authenticated user; no CVSS score has been published yet. Organizations running affected NetScaler appliances in these configurations are exposed, and affected version ranges are not specified in the available data, so defenders should consult Citrix advisory AL26-019. The flaw was added to CISA's KEV on 2026-09-09, indicating exploitation in the wild; ransomware use is unknown, no public PoC is known, and EPSS assigns a 3.4% probability of exploitation within 30 days (88th percentile). Do: Prioritize applying vendor fixes or mitigations per Citrix advisory AL26-019 in line with CISA BOD 26-04, focusing first on internet-facing appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy). Until patched, restrict internet exposure and review VPN/AAA authentication logs for signs of unauthenticated access, following CISA's Forensics Triage Requirements if compromise is suspected. | 9.3 | 6% | KEV PoC |
| largeon the order of 10,000-100,000 internet-exposed NetScaler ADC/Gateway appliances |
Full article458 words · extracted from cybersecuritynews.com · click to collapse
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026.
CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a Gateway service. This includes deployments supporting SSL VPN, ICA Proxy, CVPN, and RDP Proxy functions.
The flaw is categorized as CWE-288, Authentication Bypass Using an Alternate Path or Channel. It could allow a remote, unauthenticated attacker to bypass login protections and access functionality that normally requires valid credentials.
Because NetScaler appliances are commonly deployed at the edge of corporate networks to provide remote access, successful exploitation could expose sensitive applications and internal services.
Citrix released security updates for the vulnerability on August 19, 2026. Exploitation activity was subsequently detected after a credible proof-of-concept exploit became publicly available.
Citrix NetScaler Authentication Bypass Vulnerability Exploited
Security researchers observed attack requests targeting honeypot systems beginning on September 3, with 56 attempts logged through September 8. Available reporting indicates attempted exploitation but does not independently confirm that attackers successfully compromised production environments using the flaw.
The issue affects NetScaler ADC and NetScaler Gateway version 14.1 releases before 14.1-73.32, as well as version 13.1 releases before 13.1-63.21.
Citrix NetScaler ADC FIPS builds before 14.1-73.32, and NetScaler ADC FIPS and NDcPP builds before 13.1-37.277 are also affected. Organizations should upgrade to the corresponding fixed builds or later releases.
Newer vulnerable installations require specific configuration conditions, including use as a SAML identity provider. Earlier builds can be affected when configured as a Gateway or AAA virtual server.
Administrators should therefore identify all internet-facing NetScaler instances, confirm their firmware version, and review AAA, Gateway, VPN, and SAML settings.
CISA’s inclusion of CVE-2026-19490 in the KEV catalog means agencies must prioritize remediation under Binding Operational Directive 26-04. The agency also requires forensic triage for affected assets, emphasizing that patching alone may not be sufficient when exposure or suspicious activity is identified.
Security teams should examine appliance logs for anomalous authentication events, unexpected requests, configuration modifications, new administrator sessions, and unusual outbound connections.
Organizations should isolate potentially compromised appliances, preserve evidence, rotate relevant credentials, and assess downstream systems accessible through the affected gateway.
No ransomware use has been confirmed for CVE-2026-19490 so far. However, the combination of public exploit code, internet-facing VPN infrastructure, and observed exploitation attempts makes patching an urgent priority for all organizations running affected Citrix NetScaler deployments.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/cisa-citrix-netscaler-authentication/