ZeroDayAlert

CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

Citrix NetScaler Added to KEV 2026-09-09 Federal due 2026-09-12 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Citrix NetScaler ADC and NetScaler Gateway installations configured to provide authentication services are affected. This includes deployments operating as an AAA virtual server, SSL VPN gateway, ICA Proxy, CVPN, or RDP Proxy. The vulnerability allows unauthenticated remote access to bypass authentication entirely, regardless of configured credentials or multi-factor authentication policies.

How to check whether this touches you

  • Search your asset inventory for Citrix NetScaler ADC or NetScaler Gateway appliances.
  • Establish whether any of these appliances are configured as an AAA virtual server, SSL VPN endpoint, ICA Proxy, CVPN, or RDP Proxy by reviewing configuration documentation or connecting to the management interface.
  • Confirm network reachability by attempting to reach the authentication endpoints from outside your organisation's network perimeter (or ask your network team whether these services are published externally).
  • Retrieve the running firmware version from the appliance (Administration > System > Software Releases) and compare it against Citrix's patch advisory; note that backported fixes exist and version alone is not conclusive proof of protection.

What to do

  1. Obtain Citrix's latest security advisory and patch guidance immediately; federal systems must comply with BOD 26-04 prioritisation timelines (remediation due 2026-09-12 from CISA's record date).
  2. If you cannot patch immediately, restrict network access to these appliances by IP allowlist, firewall rules, or moving them behind an additional authentication layer; document which endpoints remain exposed and to whom.
  3. Enable comprehensive logging on affected appliances (session logs, authentication logs, and admin activity logs) and configure alerts on authentication failures or suspicious bypass attempts.
  4. If the appliance is a cloud service and patching is unavailable from the vendor, evaluate whether discontinuation is necessary under BOD 26-04 guidance.
  5. Escalate to your change management and security leadership; authentication bypass on a gateway-tier appliance is a critical risk requiring expedited patching.

If you find you were exposed

Exploitation of an authentication-bypass flaw typically precedes public disclosure; check historical logs covering at least the past six months for anomalous authentication events, failed logins followed by successful sessions without credentials, or access from unexpected geographies or IP ranges. Log retention is often the limiting factor, so contact your SIEM operator or appliance administrator immediately to preserve logs before they roll off. Compare user login records against known business activity to identify sessions that may represent compromise. If you identify suspicious activity, assume internal compromise and initiate incident response procedures including credential review and lateral movement detection.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-19490 is being exploited. It cannot tell you whether NetScaler is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →