What happened
Citrix published security bulletin CTX696939 on August 19, 2026, covering two flaws in NetScaler ADC and NetScaler Gateway. The serious one is CVE-2026-19490, which Citrix describes as "authentication bypass using an alternate path" (CWE-288) with a CVSS v4.0 base score of 9.3. An unauthenticated attacker can reach it over the network with no user interaction. It only applies when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, and Citrix notes build-specific conditions tied to the SAML action configuration. The second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to denial of service that applies only when SIP ALG is enabled on a Large Scale NAT group.
When the bulletin came out, Rapid7 said it had not seen exploitation. That changed within weeks. BleepingComputer reported that a researcher at Previdian saw requests matching a public proof-of-concept hit NetScaler sensors on September 3 from three source IPs, and was careful to call these exploitation attempts, not confirmed compromises. The Hacker News reported honeypot data showing 56 attempts since September 3, 36 of them on September 8 alone. On September 9, CISA added CVE-2026-19490 to the KEV catalog based on evidence of active exploitation, with a federal remediation deadline of September 12.
Shadowserver counts over 22,000 NetScaler ADC and about 1,700 Gateway instances exposed to the internet, per BleepingComputer. How many of those are unpatched and configured in the vulnerable way is not public.
Why it matters if you run public infrastructure
NetScaler Gateway exists to sit on the internet: its job is to be the front door for remote access. An authentication bypass on that front door is about as direct a path into a network as there is. Citrix appliances have a long history here: BleepingComputer notes that CISA has tagged 23 Citrix vulnerabilities as actively exploited since November 2021, six of them used by ransomware groups. The gap between "patch available" and "exploited" was about two weeks this time, and the KEV deadline was three days. Organizations that patch appliances on a monthly cycle were behind before they started.
What to check this week
- Find every NetScaler you expose. Look for hosts under your domains that
serve
/vpn/index.htmlor/logon/LogonPoint/, or setNSC_cookies. The forgotten one is usually a second Gateway set up for a project. - Check the build on each. Run
show ns versionon the CLI. Anything on 14.1 before 14.1-73.32 or 13.1 before 13.1-63.21 (and the FIPS builds listed in the bulletin) is affected if the configuration matches. - Confirm whether the vulnerable configuration is present. Rapid7 suggests
looking for
add authentication samlAction,add authentication vserverandadd vpn vserverentries in the running configuration. - Upgrade to a fixed build: 14.1-73.32, 13.1-63.21, or the FIPS and NDcPP builds named in CTX696939, or later. Update, September 28: a later Citrix bulletin (September 27) raised the minimum builds again for two new exploited flaws; see our follow-up.
- Look for signs of compromise. Exploitation attempts started on September 3. An appliance that was reachable and unpatched since then should be checked, not just upgraded.
How Attack Surface Scan covers this
Attack Surface Scan recognizes NetScaler Gateway and ADC login pages on hosts under your verified
domains, including hosts it finds in certificate transparency logs. NetScaler does not publish its
build number to anonymous visitors, so we cannot confirm whether a given appliance is patched. For
that case NetScaler is one of the edge products where we raise a potential match:
KEV-listed CVEs such as this one, capped at medium severity and tagged potential, with
instructions for checking the real build. We do not test the bypass or attempt exploitation. See
Vulnerability matching for how matches, potential matches and KEV
prioritisation work.
Sources
- Citrix: NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 (CTX696939)
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog (September 9, 2026)
- Rapid7: CVE-2026-19490, Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
- BleepingComputer: Critical Citrix NetScaler auth bypass now leveraged in attacks
- The Hacker News: CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline