Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and security restriction bypass on the targeted system.
CVE-2026-19490 is being exploited in the wild. Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Hence, the risk level is rated as Medium Risk.
Security Restriction Bypass
System / Technologies affected
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-73.32
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.21
NetScaler ADC FIPS BEFORE 14.1-73.32 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.277
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
