【Security Vulnerability Alert】NetScaler ADC and NetScaler Gateway contain a high-risk security vulnerability (CVE-2026-19490), please promptly verify and perform patching

 
2026/8/28 ~ 2027/2/28
View Count:42

Forwarded National Information Sharing and Analysis Center Information Security Alert NISAC-200-202608-00000011

[Content Description]
Researchers have discovered that NetScaler ADC and NetScaler Gateway contain an Authentication Bypass vulnerability (CVE-2026-19490). When devices are configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or an AAA virtual server, an unauthenticated remote attacker can bypass the authentication mechanism through an alternative path. Please promptly verify and perform patching.

[Impacted Platform]
NetScaler ADC and NetScaler Gateway versions 14.1-x to 14.1-73.32(excluding)
NetScaler ADC and NetScaler Gateway versions 13.1-x to 13.1-63.21(excluding)
NetScaler ADC FIPS versions prior to 14.1-73.32(excluding)
NetScaler ADC FIPS and NDcPP versions prior to 13.1-37.277(excluding)
Secure Private Access for Hybrid Deployments using NetScaler instances

[Recommended Actions]
The official has released a security update for the vulnerability. Please refer to the official instructions for updates. The URL is as follows: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

[Reference]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-19490
2. https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

Files
None
Top↑