CVE-2026-19490
9.5 CISA KEVCitrix · NetScaler ADC and NetScaler Gateway
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
Executive summary
This critical authentication bypass vulnerability in Citrix NetScaler ADC and Gateway is currently being exploited in the wild, posing a severe risk of total system compromise.
Vulnerability
This is an authentication bypass vulnerability occurring through an alternate path or channel, which can be triggered by an unauthenticated attacker over the network.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its critical severity and the potential for total loss of confidentiality, integrity, and availability. Successful exploitation grants an attacker unauthorized access to the affected appliance, which often serves as a gateway to internal corporate networks, potentially leading to widespread data exfiltration, lateral movement, or complete service disruption.
Remediation
Immediate Action: Review the official Citrix support article (CTX696939) immediately to identify available security updates or configuration mitigations.
Proactive Monitoring: Monitor network logs for unusual traffic patterns targeting the management interface or authentication endpoints of the NetScaler appliances.
Compensating Controls: Deploy strict access control lists on the network perimeter to restrict management access to the NetScaler appliances to trusted IP addresses only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as evidenced by the GitHub repository referenced in the enrichment data.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of this vulnerability, organizations must treat this as an emergency. Administrators should prioritize applying vendor-supplied patches or recommended mitigations immediately to prevent unauthorized access and potential compromise of the entire network environment.
More Citrix CVEs
History
- Disclosed CVE record published
- Added to CISA KEV confirmed active exploitation
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief kev section