CVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-09. EPSS: 23.2% chance of exploitation in the next 30 days.
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Affected products
- Citrix NetScaler Application Delivery Controller: from 13.1, before 13.1-37.277 (fixed in 13.1-37.277); from 13.1, before 13.1-63.21 (fixed in 13.1-63.21); from 14.1, before 14.1-73.32 (fixed in 14.1-73.32); from 14.1-66.68, up to and including 14.1-73.32
- Citrix NetScaler Gateway: from 13.1, before 13.1-63.21 (fixed in 13.1-63.21); from 14.1, before 14.1-73.32 (fixed in 14.1-73.32)
Published 2026-08-19. Last modified 2026-10-07.