Critical Citrix NetScaler bug lets attackers bypass login

Citrix has shipped a fix for a flaw that lets an attacker walk straight past the login screen on NetScaler ADC and NetScaler Gateway. Tracked as CVE-2026-19490, it carries a CVSS v4.0 base score of 9.3 and can be triggered remotely by someone with no account, no elevated privileges, and no help from a user.

What makes it urgent is where these appliances sit. NetScaler ADC handles application delivery, load balancing and SSL/TLS offloading, while NetScaler Gateway provides remote access and VPN. Both are typically parked in the DMZ with an interface facing the public internet, which is precisely the position an attacker wants. In its emergent threat write up, Rapid7 noted that authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors.

No sign of exploitation, for now

Rapid7 said that as of August 19, 2026 it had not observed evidence that CVE-2026-19490 is being exploited in the wild. That is the good news and the deadline in the same sentence. The company still recommends patching on an emergency basis, on the reasoning that Citrix products are high value targets that tend to quickly see exploitation in the wild.

The recent record supports that reasoning. On August 14 we covered the first public NetScaler remote code execution write up in three years, and in July an access broker was using a Citrix bug to plant DragonForce ransomware inside corporate networks.

Check the config before you check the version

Citrix says customers can work out whether an appliance is exposed by inspecting the NetScaler configuration rather than going on the version number alone. If the system runs an affected release and one or more of the following entries is present, Citrix says it is likely to be exploitable: a SAML action configuration ("add authentication samlAction"), or an authentication or VPN virtual server ("add authentication vserver", "add vpn vserver"). SAML is the standard that lets a gateway hand sign in off to a corporate identity provider, so in practice that covers most single sign on deployments.

Patch to 14.1-73.32 or 13.1-63.21

The fixed builds are:

No workaround has been offered, so the update is the mitigation. Citrix's own advisory carries the authoritative detail and administrators should read it before scheduling a change window. Rapid7 told its customers that a vulnerability check for Exposure Command, InsightVM and Nexpose was expected in the August 20 content release.

Perimeter appliances keep producing this kind of week precisely because they are supposed to be reachable. A device whose job is to accept connections from strangers cannot hide behind a firewall, and once an unauthenticated bypass exists for one, the only variable left is whether the patch moves faster than the exploit.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions