๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Summary
Citrix NetScaler ADC and NetScaler Gateway contain an authentication bypass vulnerability (a flaw that lets attackers skip the login process) in alternate paths or channels. When configured as an AAA virtual server (a system that manages user access and authentication) or as a Gateway for remote access (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated attacker on the internet may be able to gain access without providing valid credentials. This vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations according to Citrix vendor instructions at https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html, ensuring compliance with CISA's BOD 26-04 guidance for patching based on risk. If mitigations are unavailable for cloud services, discontinue use of the product. Organizations must evaluate each affected system's exposure to the internet and follow BOD 26-04 patching guidelines by the due date of 2026-09-12.
Vulnerability Details
EPSS: 3.4%
Yes
๐ฅ Actively Exploited
September 8, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19490
First tracked: September 9, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%